# AI Insights Source: https://docs.casebender.com/en/alerts/ai-insights Leverage AI-powered analysis for alert investigation ## Overview The AI Insights tab provides automated analysis and recommendations powered by artificial intelligence. This feature helps analysts quickly understand alert context, identify patterns, and make informed decisions about alert handling. ## Analysis Categories ### Threat Assessment * Risk scoring * Severity recommendations * Impact analysis * Confidence rating ### Pattern Recognition * Similar past alerts * Known attack patterns * Anomaly detection * Behavioral analysis ### Context Enhancement * Related external threats * Industry context * Historical perspective * Environmental factors ## AI Capabilities ### Natural Language Processing * Description analysis * Context extraction * Entity recognition * Relationship mapping ### Machine Learning Models * Pattern detection * Anomaly identification * Risk prediction * Similarity scoring ### Automated Enrichment * Threat intelligence correlation * OSINT integration * Historical data analysis * Environmental context ## Insights Display ### Summary View * Key findings * Risk assessment * Recommended actions * Critical observations ### Detailed Analysis * In-depth explanations * Supporting evidence * Confidence levels * Alternative interpretations ### Recommendations * Next steps * Investigation paths * Mitigation strategies * Resource allocation ## Interactive Features ### Insight Exploration 1. Expand detailed analysis 2. View supporting evidence 3. Access related data 4. Track insight history ### Feedback Loop * Mark insights helpful/unhelpful * Add analyst notes * Provide context * Report inaccuracies ### Custom Analysis * Request specific analysis * Focus on particular aspects * Adjust analysis parameters * Save analysis preferences ## Best Practices 1. **Analysis Review** * Validate AI findings * Cross-reference data * Document disagreements * Track accuracy 2. **Investigation Flow** * Start with summary * Explore key findings * Validate conclusions * Document decisions 3. **Feedback Quality** * Provide specific feedback * Note false positives * Suggest improvements * Share context ## Model Training ### Data Sources * Historical alerts * Analyst feedback * External threats * Industry data ### Training Process * Continuous learning * Feedback incorporation * Model updates * Performance monitoring ## Next Steps Configure automated responses Explore alert analytics # Alert Detail View Source: https://docs.casebender.com/en/alerts/detail-view Comprehensive view of individual alert information ## Overview The Alert Detail View provides a comprehensive interface for viewing and managing individual alerts. It features a rich text editor for descriptions, file attachments, and multiple tabs for different aspects of the alert. ## Layout Structure ### Main Content Area 1. **Header Section** * Back to list navigation * Severity badge * Editable title * Action buttons 2. **Description Section** * Rich text editor * Support for formatting * File attachment integration * Image embedding 3. **Attachments Section** * Image gallery with lightbox * File list with previews * Drag-and-drop upload * Attachment management ### Right Sidebar 1. **Action Panel** * Status updates * Team assignments * Tag management * Custom field updates * Case creation/linking 2. **Details Section** * Creation information * Last update timestamp * Source details * Reference information ### Activity Timeline * Chronological activity log * Status changes * Assignment updates * Comment additions * Attachment uploads ## Tab Navigation ### Observables Tab [Learn more about Observables](/en/alerts/observables) * List of associated indicators * Observable management * Type categorization * Enrichment status ### TTPs Tab [Learn more about TTPs](/en/alerts/ttps) * MITRE ATT\&CK mapping * Technique details * Procedure documentation * Tactic categorization ### Similar Alerts Tab [Learn more about Similar Alerts](/en/alerts/similar-alerts) * Related alert discovery * Similarity scoring * Merge capabilities * Pattern identification ### AI Insights Tab [Learn more about AI Insights](/en/alerts/ai-insights) * Automated analysis * Risk assessment * Recommended actions * Pattern recognition ## Editing Capabilities ### Title Editing * Direct inline editing * Auto-save functionality * Character limits * Validation rules ### Description Management * Rich text formatting * Image embedding * Link integration * Version tracking ### File Attachments * Multiple file upload * Image preview * File type support * Size limitations ## Collaboration Features ### Comments and Notes * Rich text comments * @mentions support * Reply threading * Notification integration ### Team Assignment * Single/multiple assignees * Team visibility settings * Assignment history * Auto-assignment rules ## Best Practices 1. **Content Organization** * Use clear titles * Structure descriptions well * Categorize attachments * Tag appropriately 2. **Collaboration** * Update status regularly * Document key findings * Use @mentions effectively * Keep activity log clear 3. **Investigation** * Review all tabs * Document observations * Link related items * Update findings regularly ## Next Steps Learn about observable management Explore tactics and procedures Understand alert correlation Leverage AI analysis # Alert List View Source: https://docs.casebender.com/en/alerts/list-view Navigate and manage multiple alerts efficiently ## Overview The Alert List View provides a comprehensive interface for managing multiple alerts. It offers powerful filtering, bulk operations, and quick access to alert details. ## List Features ### Toolbar Actions * **Multiple Selection**: Toggle checkbox to select multiple alerts * **Refresh**: Update the alert list in real-time * **Bulk Operations**: * Create Case from selected alerts * Merge alerts into existing case * Bulk update alert properties * Delete selected alerts ### Filtering and Search * Search by alert title and description * Filter by: * Status * Severity * Assignee * Reset filters to default view ### Selection Modes 1. **Individual Selection** * Select alerts one by one * Perform actions on specific alerts 2. **Bulk Selection** * Select all visible alerts * Select all matching alerts (across pages) * Clear selection ## List Display ### Alert List Items Each alert in the list shows: * Severity indicator * Title * Status * Assignment information * Creation timestamp * Quick action buttons ### Virtual Scrolling * Efficient handling of large alert lists * Load more functionality * Smooth scrolling performance ## Bulk Operations ### Create Case Convert multiple alerts into a new case: 1. Select relevant alerts 2. Click create case button 3. Fill case details 4. Confirm creation ### Merge with Case Add alerts to an existing case: 1. Select alerts to merge 2. Click merge button 3. Search for target case 4. Confirm merge operation ### Bulk Update Update multiple alerts simultaneously: 1. Select alerts to update 2. Click bulk update button 3. Choose fields to update 4. Apply changes ### Bulk Delete Remove multiple alerts: 1. Select alerts to delete 2. Click delete button 3. Confirm deletion ## Empty States ### No Alerts Displayed when no alerts exist: * Informative message * Guidance on creating alerts ### No Search Results Shown when filters return no results: * Suggestion to adjust filters * Option to reset search ## Best Practices 1. **Selection Management** * Use bulk selection for similar alerts * Verify selection before bulk actions * Clear selection after operations 2. **Filtering Strategy** * Start with broad filters * Refine based on results * Use search for specific alerts 3. **Bulk Operations** * Review selected items carefully * Use preview when available * Confirm irreversible actions ## Next Steps Learn about detailed alert information Master bulk alert management # Alert Observables Source: https://docs.casebender.com/en/alerts/observables Manage indicators and observables associated with alerts ## Overview The Observables tab allows you to track and manage various types of indicators associated with an alert. These observables can include IP addresses, domains, file hashes, and other relevant technical artifacts. ## Observable Types ### Network Indicators * IP Addresses * Domain Names * URLs * Email Addresses * Network Services ### File Indicators * File Hashes (MD5, SHA1, SHA256) * File Names * File Paths * File Types ### System Indicators * Registry Keys * Process Names * System Commands * User Accounts ### Custom Indicators * Custom Observable Types * Organization-specific Indicators * Industry-specific Artifacts ## Managing Observables ### Adding Observables 1. Click "Add Observable" button 2. Select observable type 3. Enter observable value 4. Add optional description 5. Set TLP/PAP levels if applicable ### Bulk Operations * Import multiple observables * Export observable list * Bulk update TLP/PAP * Bulk delete observables ### Observable Properties * Type classification * Value * Description * TLP (Traffic Light Protocol) level * PAP (Permissible Actions Protocol) level * First/Last seen timestamps * Source information ## Observable Enrichment ### Automatic Enrichment * Reputation data * Geolocation information * WHOIS data * Historical context * Related indicators ### Manual Analysis * Add analysis notes * Link to external sources * Document investigation findings * Tag related observables ## Visualization ### List View * Sortable columns * Quick filters * Type indicators * Enrichment status ### Relationship View * Observable connections * Related alerts * Common patterns * Timeline visualization ## Best Practices 1. **Data Quality** * Validate observable format * Remove false positives * Document context * Maintain consistent format 2. **Enrichment** * Review enrichment data * Update stale information * Document findings * Link related data 3. **Organization** * Use consistent naming * Group related observables * Tag effectively * Document relationships ## Next Steps Explore tactics and procedures Find related alerts # Similar Alerts Source: https://docs.casebender.com/en/alerts/similar-alerts Discover and analyze related alerts ## Overview The Similar Alerts tab helps identify and analyze alerts that may be related to the current alert. This feature uses various correlation methods to find potential connections and patterns across your alert data. ## Correlation Methods ### Content-based Similarity * Title matching * Description analysis * Observable overlap * TTP correlation ### Temporal Analysis * Time-based clustering * Frequency patterns * Sequence detection * Campaign timeline ### Contextual Correlation * Source alignment * Target comparison * Attack pattern matching * Team/Organization context ## Similarity Scoring ### Score Components * Observable match percentage * TTP overlap * Temporal proximity * Source correlation * Target alignment ### Score Interpretation * High confidence matches * Potential relationships * Weak correlations * False positives ## Alert Management ### Viewing Similar Alerts 1. Sort by similarity score 2. Filter by time range 3. Group by correlation type 4. Focus on specific attributes ### Bulk Operations * Select multiple alerts * Create case from group * Merge alerts * Update status ### Alert Comparison * Side-by-side view * Difference highlighting * Common attributes * Unique characteristics ## Pattern Analysis ### Campaign Detection * Alert clustering * Pattern identification * Campaign timeline * Attack progression ### Threat Actor Analysis * Common TTPs * Observable patterns * Target profiles * Attack methodologies ## Visualization ### Timeline View * Chronological display * Frequency analysis * Pattern highlighting * Campaign mapping ### Relationship Graph * Alert connections * Observable links * TTP relationships * Pattern visualization ## Best Practices 1. **Analysis Workflow** * Review highest scores first * Validate relationships * Document findings * Update correlation rules 2. **Pattern Recognition** * Look for campaigns * Track progression * Note anomalies * Document insights 3. **Alert Management** * Group related alerts * Create cases appropriately * Update statuses * Document relationships ## Next Steps Get AI-powered analysis Configure correlation rules # Alert TTPs Source: https://docs.casebender.com/en/alerts/ttps Track tactics, techniques, and procedures associated with alerts ## Overview The TTPs (Tactics, Techniques, and Procedures) tab provides a comprehensive view of the MITRE ATT\&CK techniques and tactics associated with an alert, helping analysts understand and document adversary behavior. ## MITRE ATT\&CK Integration ### Framework Overview * Enterprise ATT\&CK Matrix * Mobile ATT\&CK Matrix * ICS ATT\&CK Matrix * Pre-ATT\&CK Tactics ### Mapping Capabilities * Technique selection * Sub-technique support * Tactic categorization * Confidence scoring ## Managing TTPs ### Adding Techniques 1. Browse or search ATT\&CK matrix 2. Select relevant technique 3. Choose sub-techniques if applicable 4. Set confidence level 5. Add supporting evidence ### Bulk Operations * Import technique list * Export TTP mapping * Bulk update confidence * Remove multiple techniques ### TTP Properties * Technique ID * Technique name * Sub-technique details * Confidence level * Supporting evidence * Detection status * Mitigation status ## Documentation ### Evidence Collection * Observable links * Screenshot attachments * Log excerpts * Analysis notes ### Procedure Details * Implementation specifics * Tool usage * Command syntax * Execution timeline ## Analysis Features ### Pattern Recognition * Common technique combinations * Campaign correlation * Actor attribution * Similar incidents ### Impact Assessment * Technique severity * Asset scope * Business impact * Risk scoring ## Visualization ### Matrix View * ATT\&CK matrix navigation * Technique highlighting * Sub-technique expansion * Coverage mapping ### Timeline View * Technique execution order * Time-based correlation * Pattern identification * Campaign tracking ## Best Practices 1. **Technique Mapping** * Verify technique matches * Document evidence clearly * Set appropriate confidence * Link to observables 2. **Documentation** * Detail procedure specifics * Include context * Reference sources * Update findings 3. **Analysis** * Look for patterns * Compare with known actors * Assess impact * Plan mitigations ## Next Steps Find related alerts Get AI-powered analysis # Alert Analytics Source: https://docs.casebender.com/en/analytics/alert-analytics Monitor and analyze security alerts with comprehensive metrics and visualizations. ## Overview The Alert Analytics dashboard provides detailed insights into your security alerts: !\[Alert Analytics Dashboard] *Screenshot showing the main alert analytics dashboard* ## Key Metrics ### Total Alerts * Total number of alerts * Trend over time * Percentage changes * Alert volume patterns !\[Total Alerts Card] *Screenshot showing the total alerts metric card* ### Alert Status Distribution View alerts by status: * New alerts * In Progress * Imported * Duplicated * False Positive * Ignored !\[Alert Status Distribution] *Screenshot showing the pie chart of alert status distribution* ### Alert Trend Analysis Track alert patterns over time: * Daily alert volumes * Weekly trends * Monthly comparisons * Custom date ranges !\[Alert Trend Chart] *Screenshot showing the alert trend line chart* ### Severity Analysis Monitor alerts by severity level: * Critical alerts * High severity * Medium severity * Low severity Each severity level shows: * Current count * Historical trend * Pattern analysis * Impact assessment !\[Severity Analysis] *Screenshot showing the severity analysis charts* ### Top Alert Tags View most common alert tags: * Tag frequency * Usage patterns * Category distribution * Trend analysis !\[Top Tags Chart] *Screenshot showing the top alert tags bar chart* ## Interactive Features ### Date Range Selection Filter data by time period: * Last 7 days * Last 30 days * Last 90 days * Custom range * Real-time updates ### Export Options Export your analytics: * PDF reports * CSV data export * Scheduled exports * Custom formatting ### Visualization Controls Customize your view: * Chart types * Data grouping * Sorting options * Filter controls ## Best Practices ### 1. Regular Monitoring * Check daily volumes * Track severity trends * Monitor false positives * Analyze patterns ### 2. Performance Analysis * Response times * Resolution rates * Team efficiency * Quality metrics ### 3. Trend Analysis * Identify patterns * Predict volumes * Plan resources * Optimize workflows ### 4. Report Generation * Schedule reports * Share insights * Document findings * Track progress ## Related Documentation * [Case Analytics](./case-analytics.mdx) * [Task Analytics](./task-analytics.mdx) * [Analyst Performance](./analyst-performance.mdx) # Analyst Performance Source: https://docs.casebender.com/en/analytics/analyst-performance Track and analyze individual and team performance metrics for security analysts. ## Overview The Analyst Performance dashboard provides insights into individual and team performance: !\[Analyst Performance Dashboard] *Screenshot showing the main analyst performance dashboard* ## Key Metrics ### Cases Resolved Track case resolution metrics: * Total cases resolved * Resolution rate * Time to resolution * Case complexity !\[Cases Resolved Card] *Screenshot showing the cases resolved metric card* ### Alerts Processed Monitor alert handling: * Total alerts processed * Processing rate * Alert types * False positive rate !\[Alerts Processed Card] *Screenshot showing the alerts processed metric card* ### Average Response Time Measure response efficiency: * Initial response time * Resolution time * SLA compliance * Time by priority !\[Response Time Card] *Screenshot showing the average response time metric card* ### Accuracy Rate Track quality metrics: * Decision accuracy * False positive identification * Quality assessment * Improvement trends !\[Accuracy Rate Card] *Screenshot showing the accuracy rate metric card* ## Performance Analysis ### Individual Metrics Track per-analyst performance: * Workload distribution * Specialization areas * Efficiency metrics * Quality indicators ### Team Metrics Monitor team performance: * Team capacity * Collaboration patterns * Knowledge sharing * Resource utilization ## Best Practices ### 1. Performance Monitoring * Regular reviews * Goal tracking * Skill development * Process improvement ### 2. Quality Management * Accuracy tracking * Error analysis * Training needs * Best practices sharing ### 3. Resource Optimization * Workload balancing * Skill matching * Capacity planning * Team coordination ### 4. Continuous Improvement * Performance feedback * Training programs * Process optimization * Team development ## Related Documentation * [Alert Analytics](./alert-analytics.mdx) * [Case Analytics](./case-analytics.mdx) * [Task Analytics](./task-analytics.mdx) # Case Analytics Source: https://docs.casebender.com/en/analytics/case-analytics Track and analyze case management metrics with comprehensive visualizations and insights. ## Overview The Case Analytics dashboard provides detailed insights into your case management: !\[Case Analytics Dashboard] *Screenshot showing the main case analytics dashboard* ## Key Metrics ### Total Cases * Total number of cases * Trend over time * Percentage changes * Case volume patterns !\[Total Cases Card] *Screenshot showing the total cases metric card* ### Case Status Distribution View cases by status: * New cases * In Progress * Under Review * Resolved * Closed * Blocked !\[Case Status Distribution] *Screenshot showing the pie chart of case status distribution* ### Case Trend Analysis Track case patterns over time: * Daily case volumes * Weekly trends * Monthly comparisons * Custom date ranges !\[Case Trend Chart] *Screenshot showing the case trend line chart* ### Severity Analysis Monitor cases by severity level: * Critical cases * High severity * Medium severity * Low severity Each severity level shows: * Current count * Historical trend * Pattern analysis * Impact assessment !\[Severity Analysis] *Screenshot showing the severity analysis charts* ### Top Case Tags View most common case tags: * Tag frequency * Usage patterns * Category distribution * Trend analysis !\[Top Tags Chart] *Screenshot showing the top case tags bar chart* ## Interactive Features ### Date Range Selection Filter data by time period: * Last 7 days * Last 30 days * Last 90 days * Custom range * Real-time updates ### Export Options Export your analytics: * PDF reports * CSV data export * Scheduled exports * Custom formatting ### Visualization Controls Customize your view: * Chart types * Data grouping * Sorting options * Filter controls ## Best Practices ### 1. Regular Monitoring * Check case volumes * Track severity trends * Monitor resolution times * Analyze patterns ### 2. Performance Analysis * Resolution rates * Response times * Team efficiency * Quality metrics ### 3. Trend Analysis * Identify patterns * Predict volumes * Plan resources * Optimize workflows ### 4. Report Generation * Schedule reports * Share insights * Document findings * Track progress ## Related Documentation * [Alert Analytics](./alert-analytics.mdx) * [Task Analytics](./task-analytics.mdx) * [Analyst Performance](./analyst-performance.mdx) # Analytics Source: https://docs.casebender.com/en/analytics/introduction Comprehensive analytics and reporting features for monitoring alerts, cases, tasks, and analyst performance. ## Overview The Analytics section provides detailed insights and metrics across different aspects of your security operations: !\[Analytics Dashboard] *Screenshot showing the main analytics dashboard with various metric cards* ## Available Dashboards ### 1. Alert Analytics Monitor and analyze security alerts: * Total alerts and trends * Alert status distribution * Severity breakdown * Alert response times * Top alert tags !\[Alert Analytics] *Screenshot showing the alert analytics dashboard* ### 2. Case Analytics Track case management metrics: * Case volume and trends * Status distribution * Severity levels * Resolution times * Case categories !\[Case Analytics] *Screenshot showing the case analytics dashboard* ### 3. Task Analytics Monitor task performance: * Task completion rates * Priority distribution * Time tracking * Team workload * Task dependencies !\[Task Analytics] *Screenshot showing the task analytics dashboard* ### 4. Analyst Performance Track individual and team performance: * Cases resolved * Alerts processed * Average response time * Accuracy rate * Team efficiency !\[Analyst Performance] *Screenshot showing the analyst performance dashboard* ## Common Features ### 1. Date Range Selection Filter data by time period: * Last 7 days * Last 30 days * Last 90 days * Custom range * Real-time updates ### 2. Export Options Export your analytics: * PDF reports * Data download * Scheduled reports * Custom formats ### 3. Visualization Types Analyze data through various charts: * Line charts for trends * Pie charts for distribution * Bar charts for comparisons * Heat maps for patterns ### 4. Interactive Elements Interact with your data: * Drill-down capabilities * Filters and sorting * Dynamic updates * Custom views ## Best Practices ### 1. Regular Monitoring * Check dashboards daily * Track key metrics * Identify trends * Address anomalies ### 2. Performance Analysis * Compare time periods * Evaluate team metrics * Monitor SLAs * Track improvements ### 3. Report Generation * Schedule regular reports * Share key findings * Document insights * Track progress ### 4. Data-Driven Decisions * Use metrics for planning * Identify bottlenecks * Optimize workflows * Allocate resources ## Next Sections * [Alert Analytics](./alert-analytics.mdx) * [Case Analytics](./case-analytics.mdx) * [Task Analytics](./task-analytics.mdx) * [Analyst Performance](./analyst-performance.mdx) # Task Analytics Source: https://docs.casebender.com/en/analytics/task-analytics Monitor and analyze task performance with comprehensive metrics and visualizations. ## Overview The Task Analytics dashboard provides detailed insights into your task management: !\[Task Analytics Dashboard] *Screenshot showing the main task analytics dashboard* ## Key Metrics ### Total Tasks * Total number of tasks * Trend over time * Percentage changes * Task volume patterns !\[Total Tasks Card] *Screenshot showing the total tasks metric card* ### Task Status Distribution View tasks by status: * Open tasks * In Progress * Under Review * Completed * Blocked * Cancelled !\[Task Status Distribution] *Screenshot showing the pie chart of task status distribution* ### Task Priority Analysis Monitor tasks by priority level: * High priority * Medium priority * Low priority Each priority level shows: * Current count * Historical trend * Completion rate * Time tracking !\[Priority Analysis] *Screenshot showing the priority analysis charts* ### Completion Rate Track task completion metrics: * Daily completion rate * Weekly trends * Monthly averages * Time to completion !\[Completion Rate Chart] *Screenshot showing the completion rate bar chart* ## Interactive Features ### Date Range Selection Filter data by time period: * Last 7 days * Last 30 days * Last 90 days * Custom range * Real-time updates ### Export Options Export your analytics: * PDF reports * CSV data export * Scheduled exports * Custom formatting ### Visualization Controls Customize your view: * Chart types * Data grouping * Sorting options * Filter controls ## Best Practices ### 1. Regular Monitoring * Check task volumes * Track priority trends * Monitor completion rates * Analyze patterns ### 2. Performance Analysis * Completion times * Response times * Team efficiency * Quality metrics ### 3. Trend Analysis * Identify patterns * Predict volumes * Plan resources * Optimize workflows ### 4. Report Generation * Schedule reports * Share insights * Document findings * Track progress ## Related Documentation * [Alert Analytics](./alert-analytics.mdx) * [Case Analytics](./case-analytics.mdx) * [Analyst Performance](./analyst-performance.mdx) # Create Alert Source: https://docs.casebender.com/en/api-reference/endpoint/alert/alert-create POST /alerts Create a new alert # Delete Alert Source: https://docs.casebender.com/en/api-reference/endpoint/alert/delete DELETE /alerts/{id} Soft delete an alert # Get Alerts Source: https://docs.casebender.com/en/api-reference/endpoint/alert/get GET /alerts Search and list alerts with filters and pagination # Get Alert by Id Source: https://docs.casebender.com/en/api-reference/endpoint/alert/get-by-id Get /alerts/{id} Retrieve a specific alert by its ID # Merge Alert with Case Source: https://docs.casebender.com/en/api-reference/endpoint/alert/merge-alert-with-case POST /alerts/{alertId}/merge/{caseId} # Get Alert Statistics Source: https://docs.casebender.com/en/api-reference/endpoint/alert/stats GET /alerts/stats Get aggregated statistics about alerts # Update Alert Source: https://docs.casebender.com/en/api-reference/endpoint/alert/update PUT /alerts/{id} Update an existing alert # Create Case Source: https://docs.casebender.com/en/api-reference/endpoint/case/create POST /cases Create a new case # Delete Case Source: https://docs.casebender.com/en/api-reference/endpoint/case/delete DELETE /cases/{id} Delete a case (soft delete) # Search Cases Source: https://docs.casebender.com/en/api-reference/endpoint/case/get GET /cases Search and list cases with filters and pagination # Get Case Source: https://docs.casebender.com/en/api-reference/endpoint/case/get-by-id GET /cases/{id} Retrieve a specific case by its ID # Get Case Statistics Source: https://docs.casebender.com/en/api-reference/endpoint/case/stats GET /cases/stats Get aggregate statistics for cases # Update Case Source: https://docs.casebender.com/en/api-reference/endpoint/case/update PUT /cases/{id} Update an existing case. Status changes to 'Closed' require all mandatory tasks to be completed unless X-Skip-Mandatory-Validation header is set with admin privileges. # Add Alert Comment Source: https://docs.casebender.com/en/api-reference/endpoint/comments/alert-comments-add POST /alerts/{alertId}/comments Add a new comment to an alert # Get Alert Comments Source: https://docs.casebender.com/en/api-reference/endpoint/comments/alert-comments-get GET /alerts/{alertId}/comments Get all comments for a specific alert # Add Case Comment Source: https://docs.casebender.com/en/api-reference/endpoint/comments/case-comments-add POST /cases/{caseId}/comments Add a new comment to a case # Get Case Comments Source: https://docs.casebender.com/en/api-reference/endpoint/comments/case-comments-get GET /cases/{caseId}/comments Get all comments for a specific case # Detailed Health Check Source: https://docs.casebender.com/en/api-reference/endpoint/health/detailed GET /health/detailed Get detailed health information including metrics # Liveness Probe Source: https://docs.casebender.com/en/api-reference/endpoint/health/liveness GET /health Check if the API service is running # Readiness Probe Source: https://docs.casebender.com/en/api-reference/endpoint/health/readiness GET /health/ready Check if the API service is ready to accept traffic # Get Case Observables Source: https://docs.casebender.com/en/api-reference/endpoint/observables/case-observables GET /cases/{caseId}/observables Get all observables for a specific case # Create Observable Source: https://docs.casebender.com/en/api-reference/endpoint/observables/create POST /observables Create a new observable/IOC # Delete Observable Source: https://docs.casebender.com/en/api-reference/endpoint/observables/delete DELETE /observables/{id} Delete an observable # Get Observable by ID Source: https://docs.casebender.com/en/api-reference/endpoint/observables/get-by-id GET /observables/{id} Retrieve a specific observable # List Observables Source: https://docs.casebender.com/en/api-reference/endpoint/observables/list GET /observables List all observables with optional filters # Get Observable Types Source: https://docs.casebender.com/en/api-reference/endpoint/observables/types GET /observable-types Get list of available observable types # Update Observable Source: https://docs.casebender.com/en/api-reference/endpoint/observables/update PUT /observables/{id} Update an existing observable # Get Case Tasks Source: https://docs.casebender.com/en/api-reference/endpoint/task/case-tasks GET /cases/{caseId}/tasks Get all tasks for a specific case # Create Task Source: https://docs.casebender.com/en/api-reference/endpoint/task/create POST /task # Delete Task Source: https://docs.casebender.com/en/api-reference/endpoint/task/delete DELETE /task/{id} # Get External Ticket Source: https://docs.casebender.com/en/api-reference/endpoint/task/external-ticket-get GET /tasks/{id}/external-ticket Get the linked external ticket (ServiceNow/Jira) for a task (FUNC-038) # Get Task by ID Source: https://docs.casebender.com/en/api-reference/endpoint/task/get-by-id GET /tasks/{id} Retrieve a specific task # Create Jira Issue Source: https://docs.casebender.com/en/api-reference/endpoint/task/jira-create POST /tasks/{id}/external-ticket/jira Create a Jira issue from a task with auto-populated data (FUNC-038) # List Tasks Source: https://docs.casebender.com/en/api-reference/endpoint/task/list GET /tasks List all tasks with optional filters including team assignment (FUNC-045) # Create ServiceNow Ticket Source: https://docs.casebender.com/en/api-reference/endpoint/task/servicenow-create POST /tasks/{id}/external-ticket/servicenow Create a ServiceNow incident from a task with auto-populated data (FUNC-038) # Update Task Source: https://docs.casebender.com/en/api-reference/endpoint/task/update PUT /tasks/{id} Update an existing task including team assignments (FUNC-045) and TLP classification (FUNC-044). TLP can only be elevated (increased), not lowered below the parent case's TLP level. # Introduction Source: https://docs.casebender.com/en/api-reference/introduction CaseBender API endpoints View the OpenAPI specification file ## Authentication All API endpoints require authentication using API keys. Include your API key in every request using one of the following methods: ### Recommended: Bearer Token Include your API key as a Bearer token in the `Authorization` header: ```bash theme={null} Authorization: Bearer cbr_live_your_api_key_here ``` ### Alternative: X-Api-Key Header You can also use the `X-Api-Key` header: ```bash theme={null} X-Api-Key: cbr_live_your_api_key_here ``` **Important**: Your API key grants access to your CaseBender instance. Keep it secure and never share it publicly. ### Creating API Keys To create API keys: 1. Log in to your CaseBender instance 2. Navigate to **Account** → **API Keys** 3. Click **Create API Key** 4. Configure the key name, description, tier, and scopes 5. **Save the key immediately** - it is displayed only once and cannot be retrieved later When you create an API key, you'll receive a single key that looks like: ``` cbr_live_a1b2c3d4e5f6g7h8i9j0... ``` ### Using API Keys Include the API key in all API requests: #### Using cURL ```bash theme={null} curl -X GET https://your-instance.casebender.com/api/v1/alerts \ -H "Authorization: Bearer YOUR_API_KEY_HERE" \ -H "Content-Type: application/json" ``` #### Using Python (requests library) ```python theme={null} import requests headers = { "Authorization": "Bearer YOUR_API_KEY_HERE", "Content-Type": "application/json" } response = requests.get( "https://your-instance.casebender.com/api/v1/alerts", headers=headers ) ``` #### Using JavaScript/Node.js (fetch) ```javascript theme={null} const response = await fetch( "https://your-instance.casebender.com/api/v1/alerts", { method: "GET", headers: { "Authorization": "Bearer YOUR_API_KEY_HERE", "Content-Type": "application/json", }, } ); ``` ### API Key Tiers API keys are assigned tiers that determine rate limits: | Tier | Requests/Minute | Requests/Hour | Burst Allowance | | ------------ | --------------- | ------------- | --------------- | | Basic | 60 | 1,000 | 10 | | Standard | 300 | 10,000 | 50 | | Professional | 1,000 | 50,000 | 100 | | Enterprise | 5,000 | 200,000 | 500 | | Unlimited | No limit | No limit | No limit | ### API Key Scopes When creating an API key, you can limit its access to specific operations: * `alerts:read` - Read alerts * `alerts:write` - Create and update alerts * `cases:read` - Read cases * `cases:write` - Create and update cases * `observables:read` - Read observables * `observables:write` - Create and update observables * `users:read` - Read user information * `admin:*` - Administrative operations ### Common Authentication Errors * **401 Unauthorized**: * Missing `Authorization` header * Invalid or expired API key * API key has been revoked or suspended * **403 Forbidden**: * API key lacks required scope for the operation * TLP/PAP access restrictions * **429 Too Many Requests**: * Rate limit exceeded for your tier ### Security Best Practices * **Never share your API key** - treat it like a password * **Rotate API keys regularly** - revoke old keys and create new ones periodically * **Use different keys for different applications** - this allows you to revoke access per application * **Set expiration dates** - configure API keys to expire automatically when possible * **Use minimum required scopes** - only grant the permissions your application needs ### Legacy Authentication (Deprecated) The legacy `x-api-key` and `x-api-secret` headers are still supported for backward compatibility but are deprecated. Please migrate to Bearer token authentication. ```bash theme={null} # Deprecated - do not use for new integrations curl -X GET https://your-instance.casebender.com/api/v1/alerts \ -H "x-api-key: YOUR_ACCESS_KEY" \ -H "x-api-secret: YOUR_SECRET_KEY" ``` # Activity Logs Source: https://docs.casebender.com/en/audits/activity-logs Track and analyze user activities and system events with comprehensive activity logging. ## Overview Activity Logs provide a detailed record of all user actions and system events: !\[Activity Logs View] *Screenshot showing the activity logs interface* ## Activity Types ### User Activities Track user interactions: * Login/logout events * Data modifications * Status changes * Document access * Configuration updates ### System Events Monitor system operations: * Automated processes * System updates * Integration events * Background tasks * Error events ## Activity Components ### Activity Records Each activity record includes: * Timestamp * User information * Action type * Affected resources * Change details ### Event Context Capture event details: * Source information * Target resources * Action parameters * Result status * Related data ### Activity Metadata Additional context: * IP address * Browser/device * Session information * Location data * Access method ## Visualization ### Timeline View Chronological display of activities: * Time-based ordering * Activity grouping * Visual indicators * Filter options * Search capabilities ### Activity Analytics Analyze activity patterns: * Usage trends * Common actions * Peak periods * User behavior * System performance ## Interactive Features ### 1. Filtering Filter activities by: * Date range * Activity type * User * Resource * Status ### 2. Search Search through activities: * Full-text search * Advanced filters * Custom queries * Saved searches * Quick filters ### 3. Export Export activity records: * PDF reports * CSV exports * Custom formats * Scheduled exports * Data selection ## Best Practices ### 1. Activity Monitoring * Regular review * Pattern analysis * Anomaly detection * Performance tracking * Security monitoring ### 2. Data Retention * Retention policies * Archival strategy * Storage optimization * Data cleanup * Compliance requirements ### 3. Security Analysis * Access patterns * Security events * Threat detection * Compliance monitoring * Audit preparation ## Related Documentation * [Change History](./change-history.mdx) * [Status Tracking](./status-tracking.mdx) * [Compliance Monitoring](./compliance-monitoring.mdx) # Change History Source: https://docs.casebender.com/en/audits/change-history Track and analyze changes to alerts, cases, and system configurations with detailed change history. ## Overview The Change History feature provides a detailed record of all modifications: !\[Change History View] *Screenshot showing the change history interface* ## Change Types ### Alert Changes Track modifications to alerts: * Status changes * Severity updates * Assignee changes * Description edits * Title modifications * TLP/PAP changes * Team updates * Tag modifications * Organization changes * Custom field updates ### Case Changes Monitor case modifications: * Status transitions * Assignment changes * Priority updates * Description edits * Team changes * Tag updates * Custom field modifications ### System Changes Track system-level changes: * Configuration updates * Integration changes * Workflow modifications * Permission updates * Role assignments ## Change Details ### Change Records Each change record includes: * Change type * Previous value * New value * Timestamp * User information * Change comments ### User Information Track who made changes: * User name * Profile picture * Email address * Role information * Team association ### Change Comments Document change context: * Change reasons * Additional notes * Related references * Decision context * Follow-up actions ## Visualization ### Timeline View Chronological display of changes: * Time-based ordering * Visual indicators * Change grouping * Filter options * Search capabilities ### Change Comparison Compare changes visually: * Side-by-side view * Highlight differences * Track modifications * Show relationships * Identify patterns ## Interactive Features ### 1. Filtering Filter change history by: * Date range * Change type * User * Entity type * Field changes ### 2. Search Search through changes: * Full-text search * Advanced filters * Custom queries * Saved searches * Quick filters ### 3. Export Export change records: * PDF reports * CSV exports * Custom formats * Scheduled exports * Data selection ## Best Practices ### 1. Change Documentation * Add clear comments * Provide context * Link related changes * Document decisions * Include references ### 2. Change Review * Regular audits * Pattern analysis * Anomaly detection * Compliance checks * Quality assurance ### 3. Change Management * Follow procedures * Document approvals * Track dependencies * Monitor impact * Update documentation ## Related Documentation * [Status Tracking](./status-tracking.mdx) * [Activity Logs](./activity-logs.mdx) * [Compliance Monitoring](./compliance-monitoring.mdx) # Compliance Monitoring Source: https://docs.casebender.com/en/audits/compliance-monitoring Monitor and ensure compliance with regulatory requirements and internal policies through comprehensive auditing. ## Overview Compliance Monitoring provides tools and features to track, analyze, and maintain regulatory compliance: !\[Compliance Monitoring View] *Screenshot showing the compliance monitoring interface* ## Compliance Features ### Policy Tracking Monitor policy adherence: * Policy requirements * Compliance status * Policy updates * Exception tracking * Violation alerts ### Regulatory Compliance Track regulatory requirements: * Regulatory frameworks * Compliance standards * Audit requirements * Documentation needs * Reporting obligations ## Monitoring Components ### Compliance Records Each compliance record includes: * Requirement details * Status information * Due dates * Responsible parties * Documentation links ### Assessment Data Track compliance assessments: * Evaluation criteria * Assessment results * Gap analysis * Remediation plans * Follow-up actions ### Documentation Maintain compliance documents: * Policy documents * Procedures * Evidence files * Audit reports * Certifications ## Visualization ### Dashboard View Comprehensive compliance overview: * Status indicators * Risk levels * Due dates * Progress tracking * Alert notifications ### Compliance Analytics Analyze compliance data: * Compliance rates * Trend analysis * Risk assessment * Performance metrics * Gap identification ## Interactive Features ### 1. Filtering Filter compliance data by: * Requirement type * Status * Due date * Risk level * Department ### 2. Search Search compliance records: * Full-text search * Advanced filters * Custom queries * Saved searches * Quick filters ### 3. Reporting Generate compliance reports: * Status reports * Audit reports * Gap analysis * Risk assessments * Executive summaries ## Best Practices ### 1. Regular Monitoring * Scheduled reviews * Status updates * Risk assessments * Gap analysis * Action tracking ### 2. Documentation Management * Version control * Evidence collection * Document organization * Access control * Retention policies ### 3. Risk Management * Risk assessment * Control testing * Issue tracking * Remediation planning * Progress monitoring ## Related Documentation * [Change History](./change-history.mdx) * [Status Tracking](./status-tracking.mdx) * [Activity Logs](./activity-logs.mdx) # Audit Logs Source: https://docs.casebender.com/en/audits/introduction Track and monitor changes across alerts, cases, and system activities with comprehensive audit logging. ## Overview The Audit Logs system provides detailed tracking of changes and activities across the platform: !\[Audit Logs Dashboard] *Screenshot showing the main audit logs interface* ## Key Features ### 1. Change Tracking Monitor changes to: * Alert status and severity * Case assignments and updates * Team modifications * Organization changes * Custom field updates ### 2. Status History Track status transitions: * Status changes * Time in each status * Change comments * User attribution * Timestamp tracking ### 3. Activity Logging Record user activities: * User actions * System events * Authentication events * API access logs * Integration activities ### 4. Compliance Tracking Monitor compliance-related metrics: * Resolution quality * Compliance scores * Risk assessments * Time to resolution * Trend analysis ## Audit Components ### Change History Each audit entry includes: * Previous and new values * Change timestamp * User information * Change comments * Related entities ### Status Tracking Monitor status workflows: * Status transitions * Duration in status * Status comments * Workflow patterns * Resolution paths ### User Attribution Track user activities: * Action performer * Affected users * Team changes * Permission updates * Role modifications ## Interactive Features ### 1. Filtering Filter audit logs by: * Date range * User * Action type * Entity type * Status changes ### 2. Export Options Export audit data: * PDF reports * CSV exports * Scheduled reports * Custom formats ### 3. Search Capabilities Search through logs: * Full-text search * Advanced filters * Custom queries * Saved searches ## Best Practices ### 1. Regular Review * Monitor changes daily * Review critical changes * Track unusual patterns * Investigate anomalies ### 2. Compliance Management * Track required changes * Monitor compliance * Document reviews * Maintain records ### 3. Security Monitoring * Review access patterns * Track authentication * Monitor API usage * Investigate alerts ### 4. Documentation * Document changes * Maintain history * Track decisions * Record comments ## Next Sections * [Change History](./change-history.mdx) * [Status Tracking](./status-tracking.mdx) * [Activity Logs](./activity-logs.mdx) * [Compliance Monitoring](./compliance-monitoring.mdx) # Status Tracking Source: https://docs.casebender.com/en/audits/status-tracking Monitor and analyze status changes and transitions with comprehensive status history tracking. ## Overview The Status Tracking feature provides detailed insights into status changes and time spent in each status: !\[Status Tracking View] *Screenshot showing the status tracking interface* ## Status History ### Status Changes Track status transitions: * Previous status * New status * Change timestamp * User information * Change comments ### Time Tracking Monitor time in each status: * Duration calculation * Status breakdowns * Time analytics * Trend analysis * SLA monitoring ## Status Components ### Status Records Each status record includes: * Status values * Transition time * Duration * User attribution * Comments ### User Information Track who made status changes: * User name * Profile picture * Role information * Team association * Change context ### Status Comments Document status changes: * Change reasons * Additional notes * Related issues * Decision context * Follow-up actions ## Visualization ### Timeline View Chronological display of status: * Time-based ordering * Visual indicators * Status grouping * Filter options * Search capabilities ### Status Analytics Analyze status patterns: * Time distribution * Common transitions * Bottleneck detection * Efficiency metrics * Trend analysis ## Interactive Features ### 1. Filtering Filter status history by: * Date range * Status type * User * Duration * Comments ### 2. Search Search through status changes: * Full-text search * Advanced filters * Custom queries * Saved searches * Quick filters ### 3. Export Export status records: * PDF reports * CSV exports * Custom formats * Scheduled exports * Data selection ## Best Practices ### 1. Status Documentation * Add clear comments * Provide context * Document decisions * Track dependencies * Include references ### 2. Status Review * Regular audits * Pattern analysis * Bottleneck detection * Efficiency checks * Process improvement ### 3. Time Management * Monitor durations * Track SLAs * Identify delays * Optimize workflows * Improve efficiency ## Related Documentation * [Change History](./change-history.mdx) * [Activity Logs](./activity-logs.mdx) * [Compliance Monitoring](./compliance-monitoring.mdx) # AI Features in Case Management Source: https://docs.casebender.com/en/cases/ai-features This guide covers the AI-powered features available in the case management system, designed to enhance investigation efficiency and decision-making. ## Overview AI features provide automated analysis, insights, and recommendations to help analysts work more effectively: !\[AI Features Overview] *Screenshot showing the AI features dashboard* ## AI Insights Tab ### Automated Analysis The AI Insights tab provides: 1. **Case Summary**: * Key findings * Risk assessment * Recommended actions * Similar cases 2. **Pattern Detection**: * Behavioral patterns * Attack techniques * Anomaly detection * Trend analysis !\[AI Insights Interface] *Screenshot of the AI Insights tab showing analysis results* ## Key Features ### 1. Similar Case Detection Automatically identifies related cases: * Pattern matching * Behavioral similarity * Shared indicators * Historical correlation ### 2. Threat Analysis AI-powered threat assessment: * Risk scoring * Impact analysis * Threat actor attribution * Attack pattern matching ### 3. Recommendation Engine Provides actionable recommendations: * Next steps * Investigation paths * Mitigation strategies * Resource allocation ### 4. Natural Language Processing Advanced text analysis: * Content summarization * Entity extraction * Relationship mapping * Sentiment analysis ## Using AI Features ### Accessing AI Insights 1. Open a case 2. Navigate to AI Insights tab 3. View automated analysis 4. Explore recommendations ### Interpreting Results Understanding AI outputs: * Confidence scores * Supporting evidence * Related findings * Action priorities !\[AI Results Interpretation] *Screenshot showing how to interpret AI analysis results* ## Configuration Options ### AI Feature Settings Configure AI behavior: * Analysis frequency * Confidence thresholds * Data sources * Integration points ### Model Selection Choose AI models for: * Pattern recognition * Text analysis * Risk assessment * Recommendation generation !\[AI Configuration] *Screenshot of AI feature configuration options* ## Integration Features ### External AI Services Integration with: * OpenAI services * Custom ML models * Third-party AI tools * Threat intelligence platforms ### Data Sources AI analysis uses: * Case history * Alert data * Threat intelligence * External feeds ## Best Practices ### 1. Data Quality Ensure quality inputs: * Complete case documentation * Accurate metadata * Relevant observables * Clear descriptions ### 2. AI Assistance Effective use of AI: * Verify AI findings * Combine with human analysis * Document AI insights * Provide feedback ### 3. Continuous Learning Improve AI performance: * Regular model updates * Feedback integration * Performance monitoring * Training data updates ## Privacy and Security ### Data Protection AI feature security: * Data encryption * Access controls * Audit logging * Privacy compliance ### Ethical Considerations Responsible AI use: * Bias prevention * Decision transparency * Human oversight * Ethical guidelines !\[Privacy Settings] *Screenshot showing AI privacy and security settings* ## Performance Metrics ### AI Effectiveness Track AI performance: * Accuracy rates * Time savings * False positive rates * User adoption ### Impact Analysis Measure business impact: * Resolution time * Decision quality * Resource efficiency * Cost savings ## Troubleshooting ### Common Issues Address AI-related problems: 1. **Analysis Delays**: * Check data sources * Verify API access * Monitor system resources 2. **Accuracy Issues**: * Review training data * Adjust thresholds * Update models * Gather feedback !\[Troubleshooting Guide] *Screenshot showing AI troubleshooting interface* ## Future Developments Upcoming AI features: * Advanced analytics * Predictive modeling * Automated reporting * Enhanced visualization For more information about working with cases, see [Working with Cases](./working-with-cases.mdx). # Creating Cases Source: https://docs.casebender.com/en/cases/creating-cases This guide explains the different ways to create cases in the system and the available options during case creation. ## Methods of Creation ### 1. Manual Creation Cases can be created manually through the user interface in several ways: * Using the "New Case" button in the cases list view * From the quick actions menu in the navigation bar * Through the case templates in the settings !\[Create Case Dialog] *Screenshot showing the case creation dialog with all available fields* ### 2. From Templates Case templates provide a standardized way to create cases with predefined fields: * Choose from available templates or start with a blank case * Templates can include pre-filled fields and default values * Organization-specific templates are supported !\[Case Templates] *Screenshot showing the template selection dialog during case creation* ### 3. From Alerts Cases can be automatically or manually created from security alerts: * Convert single alerts to cases * Merge multiple alerts into a single case * Inherit alert properties (severity, TLP, etc.) ## Required Fields When creating a case, the following fields are mandatory: * **Title**: A clear, descriptive name for the case * **Status**: Initial status (defaults to "New") * **Severity**: Impact level (1-5) * **TLP**: Traffic Light Protocol classification * **PAP**: Permissible Actions Protocol level ## Optional Fields Additional fields that can be specified during creation: * **Description**: Detailed information about the case * **Tags**: Custom labels for categorization * **Assignee**: Team member responsible for the case * **Custom Fields**: Organization-specific data fields * **Organizations**: Visibility settings for organizations ## Case Creation Settings Administrators can configure various aspects of case creation: * Default values for new cases * Required and optional fields * Available templates * Automation rules for case creation * Organization-specific settings !\[Case Settings] *Screenshot showing the administrative settings for case creation* ## Best Practices 1. **Titles**: Use clear, descriptive titles that include key information 2. **Templates**: Create templates for common case types to ensure consistency 3. **Severity**: Follow organization guidelines for severity assignment 4. **TLP/PAP**: Carefully consider information sharing restrictions 5. **Custom Fields**: Use custom fields to capture organization-specific data ## Automation Options Cases can be created automatically through various triggers: * Alert-based triggers * Integration webhooks * API endpoints * Scheduled workflows ## Next Steps After creating a case: 1. Add relevant observables and artifacts 2. Create initial tasks 3. Link related alerts 4. Assign team members 5. Add detailed documentation For more information on working with cases after creation, see [Working with Cases](./working-with-cases.mdx). # Case Management Source: https://docs.casebender.com/en/cases/introduction The Case Management system is a comprehensive solution for tracking, managing, and resolving security incidents and investigations. This documentation covers all aspects of the case management functionality. ## Overview Cases are the core entities for managing security incidents, investigations, and related activities. Each case represents a distinct security event or investigation that needs to be tracked and resolved. !\[Case List View] *Screenshot showing the main case list view with filters, search, and case cards* ## Key Features * **Case Lifecycle Management**: Track cases from creation to resolution * **Customizable Status Workflows**: Configure case statuses to match your organization's processes * **Team Collaboration**: Assign cases to team members and track their progress * **Rich Metadata**: Track severity, TLP (Traffic Light Protocol), and PAP (Permissible Actions Protocol) * **Tagging System**: Organize cases with customizable tags * **Integration with Alerts**: Link related alerts to cases * **AI Insights**: Automated analysis and insights for cases (when enabled) * **Audit Trail**: Complete timeline of case activities and changes ## Case Properties ### Core Properties * **Case ID**: Unique identifier (auto-generated) * **Title**: Descriptive name of the case * **Description**: Detailed information about the case * **Status**: Current state in the workflow (New, InProgress, Closed) * **Severity**: Impact level (1-5) * **TLP**: Traffic Light Protocol classification * **PAP**: Permissible Actions Protocol level * **Tags**: Custom labels for categorization * **Custom Fields**: Organization-specific additional data ### Metadata * **Created By**: User who created the case * **Created At**: Timestamp of case creation * **Updated At**: Last modification timestamp * **Assigned To**: Team member responsible for the case * **Organizations**: Associated organizations (for multi-tenant setups) ## Related Components Cases are connected to several other components: * **Alerts**: Security alerts that triggered or are related to the case * **Observables**: Artifacts and indicators associated with the case * **Tasks**: Action items and to-dos within the case * **TTPs**: Tactics, Techniques, and Procedures identified in the case * **Timeline**: Chronological record of case activities * **AI Insights**: AI-powered analysis and recommendations (if enabled) !\[Case Detail View] *Screenshot showing the detailed view of a case with all its components and tabs* ## Next Sections * [Creating Cases](./creating-cases.mdx) * [Case Workflows](./workflows.mdx) * [Working with Cases](./working-with-cases.mdx) * [Case Settings](./settings.mdx) * [AI Features](./ai-features.mdx) # Case Settings Source: https://docs.casebender.com/en/cases/settings This guide covers the configuration options and settings available for customizing the case management system. ## Access Settings Navigate to Settings > Cases to configure case-related options: !\[Case Settings Page] *Screenshot showing the main case settings interface* ## Status Configuration ### Managing Case Statuses Configure the available case statuses: 1. **Create Status**: * Label and description * Color coding * Stage assignment * Unique value 2. **Edit Status**: * Modify existing status properties * Update color and label * Change stage assignment 3. **Delete Status**: * Remove unused statuses * Handle cases with deleted status !\[Status Management] *Screenshot of the status management interface* ## Templates ### Case Templates Create and manage case templates: * Define default values * Set required fields * Create specialized templates * Organization-specific templates ### Template Properties Configure for each template: * Name and description * Default field values * Required fields * Automation rules * Team assignments !\[Template Configuration] *Screenshot showing template creation and editing* ## Field Configuration ### Custom Fields Add organization-specific fields: * Field types (text, number, date, etc.) * Required/optional settings * Default values * Field validation ### Field Display Configure how fields appear: * Field order * Grouping * Visibility conditions * Mobile display !\[Custom Fields] *Screenshot of custom field configuration* ## Automation Settings ### Workflow Rules Configure automated actions: 1. **Triggers**: * Case creation * Status changes * Field updates * Time-based events 2. **Actions**: * Status updates * Assignments * Notifications * Integration calls !\[Workflow Automation] *Screenshot of workflow automation settings* ## Team Settings ### Access Control Configure team-based settings: * Role permissions * Team assignments * Visibility rules * Collaboration settings ### Assignment Rules Set up case assignment rules: * Auto-assignment * Load balancing * Skill-based routing * Backup assignments !\[Team Configuration] *Screenshot showing team and assignment settings* ## Integration Settings ### External Systems Configure integrations with: * SIEM platforms * Ticketing systems * Communication tools * Custom applications ### API Configuration Manage API settings: * API keys * Webhook endpoints * Rate limits * Authentication !\[Integration Settings] *Screenshot of integration configuration* ## Notification Settings ### Email Notifications Configure email alerts for: * Case creation * Status changes * Assignments * Comments * Due dates ### Other Notifications Set up notifications for: * Slack/Teams * Mobile push * Custom webhooks * System alerts !\[Notification Configuration] *Screenshot showing notification settings* ## Analytics Settings ### Metrics Configuration Configure tracking for: * Response times * Resolution rates * Team performance * Custom metrics ### Reporting Set up report templates: * Case summaries * Team reports * Custom reports * Scheduled reports !\[Analytics Settings] *Screenshot of analytics and reporting configuration* ## Best Practices 1. **Status Management**: * Keep status list concise * Use clear color coding * Document status meanings 2. **Templates**: * Create templates for common cases * Review and update regularly * Get team feedback 3. **Fields**: * Only add necessary fields * Use clear field labels * Group related fields 4. **Automation**: * Start with simple rules * Test thoroughly * Monitor performance 5. **Permissions**: * Follow least privilege * Regular access review * Document role requirements For information about working with cases, see [Working with Cases](./working-with-cases.mdx). # Case Workflows Source: https://docs.casebender.com/en/cases/workflows Case workflows define how cases progress through your organization's incident response or investigation process. This guide explains how to work with and customize case workflows. ## Case Status Stages Cases can be in one of three main stages: 1. **New**: Recently created cases requiring initial triage 2. **InProgress**: Cases actively being worked on 3. **Closed**: Resolved or completed cases !\[Case Status Flow] *Diagram showing the progression of cases through different status stages* ## Customizable Status Labels Within each stage, organizations can create custom status labels: * **New Stage**: Initial Triage, Pending Review, etc. * **InProgress Stage**: Investigating, Waiting for Response, etc. * **Closed Stage**: Resolved, False Positive, etc. ### Status Properties Each status has the following properties: * **Label**: Display name for the status * **Color**: Visual indicator for the status * **Stage**: Associated workflow stage * **Can Delete**: Whether the status can be removed * **Value**: Unique identifier for the status !\[Status Management] *Screenshot of the status management interface in settings* ## Workflow Automation ### Triggers Workflows can be automated based on various triggers: * **CaseCreated**: When a new case is created * **CaseUpdated**: When case properties are modified * **CaseDeleted**: When a case is removed ### Actions Automated actions can include: * Status changes * Assignment updates * Notification generation * Integration with external systems * Custom script execution ## Status Transitions ### Manual Transitions Users can manually change case status based on their permissions: * From the case detail view * Through bulk actions in the case list * Via the API ### Automated Transitions Status can change automatically based on: * Time-based rules * Alert updates * External system triggers * Workflow automation rules ## Permissions and Roles Status management is controlled by user permissions: * **caseUpdate**: Required to change case status * **caseCreate**: Needed to set initial status * **caseDelete**: Required for certain status transitions ## Workflow Analytics Track and analyze your case workflows: * Time in each status * Common transition patterns * Bottlenecks and delays * Team performance metrics !\[Workflow Analytics] *Screenshot showing workflow analytics dashboard* ## Best Practices 1. **Status Clarity**: Use clear, descriptive status names 2. **Color Coding**: Choose distinct colors for different stages 3. **Automation**: Automate routine status changes 4. **Metrics**: Monitor time spent in each status 5. **Documentation**: Maintain clear status transition guidelines ## Configuration ### Adding New Status 1. Navigate to Case Status settings 2. Click "Add Status" 3. Configure properties: * Label * Stage * Color * Value 4. Save changes ### Modifying Workflows 1. Access Workflow settings 2. Create or edit workflow rules 3. Define triggers and actions 4. Test workflow automation 5. Deploy changes ## Integration Workflow status can integrate with: * External ticketing systems * SIEM platforms * Communication tools * Custom applications For more information on working with cases, see [Working with Cases](./working-with-cases.mdx). # Working with Cases Source: https://docs.casebender.com/en/cases/working-with-cases This guide covers the day-to-day operations and features available when working with cases in the system. ## Case Detail View The case detail view is your primary workspace for managing cases: !\[Case Detail Interface] *Screenshot showing the main case detail interface with all components* ### Key Areas 1. **Header**: Case title, ID, and quick actions 2. **Details Panel**: Core case properties and metadata 3. **Tabs**: Access different case components 4. **Activity Timeline**: Recent updates and changes ## Case Components ### 1. Tasks Tasks help track action items within a case: * Create and assign tasks * Set priorities and due dates * Track task completion * Add task notes and attachments !\[Tasks Tab] *Screenshot of the tasks management interface* ### 2. Observables Manage artifacts and indicators: * Add files, IPs, domains, and other observables * Automatic enrichment * Relationship visualization * Threat intelligence lookup !\[Observables Tab] *Screenshot showing observable management and analysis* ### 3. TTPs (Tactics, Techniques, and Procedures) Map case activities to known attack patterns: * MITRE ATT\&CK® framework integration * Custom TTP definitions * Visual attack flow mapping * Related procedure documentation !\[TTPs Tab] *Screenshot of the TTP mapping interface* ### 4. Timeline Chronological view of case activities: * Automatic event tracking * Manual timeline entries * Filter and search capabilities * Evidence timeline reconstruction !\[Timeline Tab] *Screenshot showing the case timeline view* ### 5. AI Insights AI-powered analysis and recommendations: * Automated case analysis * Similar case detection * Recommendation engine * Pattern recognition !\[AI Insights Tab] *Screenshot of AI-powered insights and recommendations* ## Case Actions ### Assignment and Collaboration * Assign cases to team members * Transfer ownership * Add collaborators * Team notifications ### Linking and Relationships * Link related cases * Connect alerts * Establish observable relationships * Create case groups ### Documentation * Add notes and comments * Attach files and evidence * Generate reports * Export case data ### Case Merging When multiple cases are related: 1. Select cases to merge 2. Choose primary case 3. Review relationships 4. Confirm merge action ## Analysis Tools ### 1. Search and Filters * Full-text search * Advanced filtering * Saved searches * Custom views ### 2. Visualizations * Relationship graphs * Timeline views * Statistical analysis * Custom dashboards ### 3. Reporting * Case summaries * Status reports * Team metrics * Custom report templates ## Best Practices 1. **Documentation**: Keep detailed notes and updates 2. **Observables**: Add context to all observables 3. **Tasks**: Break down complex investigations 4. **Timeline**: Document key findings and decisions 5. **Collaboration**: Use comments for team communication ## Keyboard Shortcuts Common actions have keyboard shortcuts: * `Ctrl/Cmd + S`: Save changes * `Ctrl/Cmd + E`: Edit mode * `Ctrl/Cmd + F`: Search * `Esc`: Cancel/Close ## Mobile Access The case interface is responsive and supports: * Mobile viewing * Basic editing * Task management * Status updates !\[Mobile Interface] *Screenshot showing the mobile case interface* ## Integration Features Cases integrate with: * Email notifications * Slack/Teams messages * Webhook triggers * External systems For information about case workflows and status management, see [Case Workflows](./workflows.mdx). # Deploy to AWS Source: https://docs.casebender.com/en/deployment/aws Deploy CaseBender on Amazon Web Services (AWS) ## Overview This guide walks you through deploying CaseBender on AWS using pre-built Docker images with Amazon ECS (Elastic Container Service) and Fargate. ## Prerequisites 1. [AWS Account](https://aws.amazon.com/) 2. [AWS CLI](https://aws.amazon.com/cli/) installed and configured 3. [Docker](https://docs.docker.com/get-docker/) installed ## Step 1: Initial Setup ### Install and Configure AWS CLI ```bash macOS theme={null} # Using Homebrew brew install awscli # Configure AWS CLI aws configure # Configure Docker for ECR aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin $(aws sts get-caller-identity --query Account --output text).dkr.ecr.us-east-1.amazonaws.com ``` ```bash Linux theme={null} # Install AWS CLI curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" unzip awscliv2.zip sudo ./aws/install # Configure AWS CLI aws configure # Configure Docker for ECR aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin $(aws sts get-caller-identity --query Account --output text).dkr.ecr.us-east-1.amazonaws.com ``` ```powershell Windows theme={null} # Download and run the AWS CLI MSI installer # https://awscli.amazonaws.com/AWSCLIV2.msi # Configure AWS CLI aws configure # Configure Docker for ECR aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin $(aws sts get-caller-identity --query Account --output text).dkr.ecr.us-east-1.amazonaws.com ``` ## Step 2: Set Up AWS Infrastructure ### Create S3 Bucket for Storage ```bash theme={null} # Create S3 bucket aws s3 create-bucket \ --bucket casebender-storage \ --region us-east-1 # Enable versioning (optional) aws s3api put-bucket-versioning \ --bucket casebender-storage \ --versioning-configuration Status=Enabled # Create IAM user for S3 access aws iam create-user --user-name casebender-storage-user # Create and attach policy aws iam create-policy \ --policy-name casebender-storage-policy \ --policy-document '{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:PutObject", "s3:GetObject", "s3:DeleteObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::casebender-storage", "arn:aws:s3:::casebender-storage/*" ] } ] }' # Attach policy to user aws iam attach-user-policy \ --user-name casebender-storage-user \ --policy-arn arn:aws:iam::YOUR_ACCOUNT_ID:policy/casebender-storage-policy # Create access keys aws iam create-access-key --user-name casebender-storage-user ``` ### Create a VPC ```bash theme={null} # Create VPC aws ec2 create-vpc \ --cidr-block 10.0.0.0/16 \ --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=casebender-vpc}]' # Enable DNS hostnames aws ec2 modify-vpc-attribute \ --vpc-id \ --enable-dns-hostnames ``` ### Create Subnets ```bash theme={null} # Create public subnets aws ec2 create-subnet \ --vpc-id \ --cidr-block 10.0.1.0/24 \ --availability-zone us-east-1a \ --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=casebender-public-1a}]' aws ec2 create-subnet \ --vpc-id \ --cidr-block 10.0.2.0/24 \ --availability-zone us-east-1b \ --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=casebender-public-1b}]' ``` ### Set Up RDS (PostgreSQL) ```bash theme={null} # Create DB subnet group aws rds create-db-subnet-group \ --db-subnet-group-name casebender-db-subnet \ --db-subnet-group-description "Subnet group for CaseBender RDS" \ --subnet-ids "" "" # Create RDS instance aws rds create-db-instance \ --db-instance-identifier casebender-db \ --db-instance-class db.t3.medium \ --engine postgres \ --master-username superadmin \ --master-user-password \ --allocated-storage 20 \ --db-subnet-group-name casebender-db-subnet ``` ### Set Up ElastiCache (Redis) ```bash theme={null} # Create cache subnet group aws elasticache create-cache-subnet-group \ --cache-subnet-group-name casebender-cache-subnet \ --cache-subnet-group-description "Subnet group for CaseBender Redis" \ --subnet-ids "" "" # Create Redis cluster aws elasticache create-cache-cluster \ --cache-cluster-id casebender-redis \ --engine redis \ --cache-node-type cache.t3.micro \ --num-cache-nodes 1 \ --cache-subnet-group-name casebender-cache-subnet ``` ## Step 3: Create ECR Repositories ```bash theme={null} # Create repositories for each service aws ecr create-repository --repository-name casebender/app aws ecr create-repository --repository-name casebender/workflow-processor aws ecr create-repository --repository-name casebender/misp-processor # Get the AWS account ID AWS_ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text) # Pull CaseBender images docker pull casebender/casebender:latest docker pull casebender/workflow-processor:latest docker pull casebender/misp-processor:latest # Tag images for ECR docker tag casebender/casebender:latest ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/app:latest docker tag casebender/workflow-processor:latest ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/workflow-processor:latest docker tag casebender/misp-processor:latest ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/misp-processor:latest # Push images to ECR docker push ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/app:latest docker push ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/workflow-processor:latest docker push ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/misp-processor:latest ``` ## Step 4: Create ECS Cluster ```bash theme={null} # Create ECS cluster aws ecs create-cluster --cluster-name casebender-cluster # Create task execution role aws iam create-role \ --role-name ecsTaskExecutionRole \ --assume-role-policy-document file://task-execution-assume-role.json # Attach policy aws iam attach-role-policy \ --role-name ecsTaskExecutionRole \ --policy-arn arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy ``` ## Step 5: Create Task Definitions Create task definition JSON files for each service: ```json theme={null} { "family": "casebender-app", "networkMode": "awsvpc", "requiresCompatibilities": ["FARGATE"], "cpu": "1024", "memory": "2048", "executionRoleArn": "arn:aws:iam:::role/ecsTaskExecutionRole", "containerDefinitions": [ { "name": "app", "image": ".dkr.ecr.us-east-1.amazonaws.com/casebender/app:latest", "portMappings": [ { "containerPort": 3000, "protocol": "tcp" } ], "environment": [ { "name": "POSTGRES_PRISMA_URL", "value": "postgresql://superadmin:password@casebender-db.xxxxx.region.rds.amazonaws.com:5432/casebender" }, { "name": "REDIS_URL", "value": "redis://casebender-redis.xxxxx.region.cache.amazonaws.com:6379" }, { "name": "AWS_S3_BUCKET", "value": "casebender-storage" }, { "name": "AWS_S3_REGION", "value": "us-east-1" } ], "secrets": [ { "name": "AUTH_SECRET", "valueFrom": "arn:aws:secretsmanager:region:account:secret:auth-secret" }, { "name": "AUTH_SALT", "valueFrom": "arn:aws:secretsmanager:region:account:secret:auth-salt" } ], "logConfiguration": { "logDriver": "awslogs", "options": { "awslogs-group": "/ecs/casebender", "awslogs-region": "us-east-1", "awslogs-stream-prefix": "app" } } } ] } ``` Register the task definitions: ```bash theme={null} # Register task definitions aws ecs register-task-definition --cli-input-json file://app-task-definition.json aws ecs register-task-definition --cli-input-json file://workflow-processor-task-definition.json aws ecs register-task-definition --cli-input-json file://misp-processor-task-definition.json ``` ## Step 6: Create Application Load Balancer ```bash theme={null} # Create ALB aws elbv2 create-load-balancer \ --name casebender-alb \ --subnets \ --security-groups # Create target group aws elbv2 create-target-group \ --name casebender-tg \ --protocol HTTP \ --port 3000 \ --vpc-id \ --target-type ip # Create listener aws elbv2 create-listener \ --load-balancer-arn \ --protocol HTTPS \ --port 443 \ --certificates CertificateArn= \ --default-actions Type=forward,TargetGroupArn= ``` ## Step 7: Create ECS Services ```bash theme={null} # Create service for main app aws ecs create-service \ --cluster casebender-cluster \ --service-name casebender-app \ --task-definition casebender-app \ --desired-count 2 \ --launch-type FARGATE \ --network-configuration "awsvpcConfiguration={subnets=[,],securityGroups=[],assignPublicIp=ENABLED}" \ --load-balancers "targetGroupArn=,containerName=app,containerPort=3000" # Create services for processors aws ecs create-service \ --cluster casebender-cluster \ --service-name workflow-processor \ --task-definition casebender-workflow-processor \ --desired-count 1 \ --launch-type FARGATE \ --network-configuration "awsvpcConfiguration={subnets=[,],securityGroups=[],assignPublicIp=ENABLED}" aws ecs create-service \ --cluster casebender-cluster \ --service-name misp-processor \ --task-definition casebender-misp-processor \ --desired-count 1 \ --launch-type FARGATE \ --network-configuration "awsvpcConfiguration={subnets=[,],securityGroups=[],assignPublicIp=ENABLED}" ``` ## Step 8: Set Up Route 53 (Optional) If you're using a custom domain: ```bash theme={null} # Create hosted zone (if not exists) aws route53 create-hosted-zone \ --name yourdomain.com \ --caller-reference $(date +%s) # Create A record aws route53 change-resource-record-sets \ --hosted-zone-id \ --change-batch '{ "Changes": [{ "Action": "CREATE", "ResourceRecordSet": { "Name": "yourdomain.com", "Type": "A", "AliasTarget": { "HostedZoneId": "", "DNSName": "", "EvaluateTargetHealth": true } } }] }' ``` ## Monitoring and Maintenance ### Set Up CloudWatch Alarms ```bash theme={null} # Create CPU utilization alarm aws cloudwatch put-metric-alarm \ --alarm-name casebender-cpu-alarm \ --alarm-description "CPU utilization exceeded 80%" \ --metric-name CPUUtilization \ --namespace AWS/ECS \ --statistic Average \ --period 300 \ --threshold 80 \ --comparison-operator GreaterThanThreshold \ --dimensions Name=ClusterName,Value=casebender-cluster \ --evaluation-periods 2 \ --alarm-actions ``` ### View Logs ```bash theme={null} # View service logs aws logs get-log-events \ --log-group-name /ecs/casebender \ --log-stream-name app/ ``` ### Update Services ```bash theme={null} # Update service with new task definition aws ecs update-service \ --cluster casebender-cluster \ --service casebender-app \ --task-definition casebender-app:NEW_REVISION ``` ## Cost Optimization 1. Use Fargate Spot for non-critical workloads 2. Implement auto-scaling based on metrics 3. Choose appropriate instance sizes 4. Use Reserved Instances for predictable workloads ## Security Best Practices 1. Use AWS Secrets Manager for sensitive data 2. Implement WAF rules 3. Enable VPC Flow Logs 4. Regular security group audits 5. Enable AWS GuardDuty ## Next Steps * Set up CI/CD pipeline with AWS CodePipeline * Configure backup strategies * Implement monitoring and alerting * Review security best practices # Deploy to Azure Source: https://docs.casebender.com/en/deployment/azure Deploy CaseBender on Microsoft Azure ## Overview This guide walks you through deploying CaseBender on Azure using pre-built Docker images with Azure Container Apps and managed services. ## Prerequisites 1. [Azure Account](https://azure.microsoft.com/) 2. [Azure CLI](https://docs.microsoft.com/en-us/cli/azure/install-azure-cli) installed 3. [Docker](https://docs.docker.com/get-docker/) installed ## Step 1: Initial Setup ### Install and Configure Azure CLI ```bash macOS theme={null} # Using Homebrew brew install azure-cli # Login to Azure az login # Configure Docker for ACR az acr login --name casebenderacr ``` ```bash Linux theme={null} # Install Azure CLI curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash # Login to Azure az login # Configure Docker for ACR az acr login --name casebenderacr ``` ```powershell Windows theme={null} # Using winget winget install -e --id Microsoft.AzureCLI # Login to Azure az login # Configure Docker for ACR az acr login --name casebenderacr ``` ### Initialize Project ```bash theme={null} # Set variables RESOURCE_GROUP="casebender-rg" LOCATION="eastus" # Create resource group az group create --name $RESOURCE_GROUP --location $LOCATION # Enable required services az provider register --namespace Microsoft.ContainerRegistry az provider register --namespace Microsoft.App az provider register --namespace Microsoft.Storage ``` ## Step 2: Set Up Azure Infrastructure ### Create Storage Account ```bash theme={null} # Create storage account az storage account create \ --name casebenderstorage \ --resource-group $RESOURCE_GROUP \ --location $LOCATION \ --sku Standard_LRS \ --encryption-services blob # Create blob container az storage container create \ --name casebender \ --account-name casebenderstorage \ --auth-mode key \ --public-access off # Get storage account key STORAGE_KEY=$(az storage account keys list \ --account-name casebenderstorage \ --resource-group $RESOURCE_GROUP \ --query '[0].value' -o tsv) # Create managed identity for storage access az identity create \ --name casebender-storage-identity \ --resource-group $RESOURCE_GROUP # Get managed identity ID IDENTITY_ID=$(az identity show \ --name casebender-storage-identity \ --resource-group $RESOURCE_GROUP \ --query id -o tsv) # Assign Storage Blob Data Contributor role az role assignment create \ --assignee-object-id $(az identity show --name casebender-storage-identity --resource-group $RESOURCE_GROUP --query principalId -o tsv) \ --role "Storage Blob Data Contributor" \ --scope $(az storage account show --name casebenderstorage --resource-group $RESOURCE_GROUP --query id -o tsv) ``` ### Set Up Azure Database for PostgreSQL ```bash theme={null} # Create PostgreSQL server az postgres flexible-server create \ --resource-group $RESOURCE_GROUP \ --name casebender-db \ --admin-user superadmin \ --admin-password \ --sku-name Standard_B2s \ --storage-size 32 \ --version 14 # Create database az postgres flexible-server db create \ --resource-group $RESOURCE_GROUP \ --server-name casebender-db \ --database-name casebender ``` ### Set Up Azure Cache for Redis ```bash theme={null} # Create Redis cache az redis create \ --resource-group $RESOURCE_GROUP \ --name casebender-redis \ --sku Basic \ --vm-size c0 \ --location $LOCATION ``` ## Step 3: Create and Configure Container Registry ```bash theme={null} # Create Azure Container Registry az acr create \ --resource-group $RESOURCE_GROUP \ --name casebenderacr \ --sku Standard \ --admin-enabled true # Get registry credentials ACR_USERNAME=$(az acr credential show --name casebenderacr --query username -o tsv) ACR_PASSWORD=$(az acr credential show --name casebenderacr --query "passwords[0].value" -o tsv) # Pull CaseBender images docker pull casebender/casebender:latest docker pull casebender/workflow-processor:latest docker pull casebender/misp-processor:latest # Tag images for ACR docker tag casebender/casebender:latest casebenderacr.azurecr.io/casebender/app:latest docker tag casebender/workflow-processor:latest casebenderacr.azurecr.io/casebender/workflow-processor:latest docker tag casebender/misp-processor:latest casebenderacr.azurecr.io/casebender/misp-processor:latest # Push images to ACR docker push casebenderacr.azurecr.io/casebender/app:latest docker push casebenderacr.azurecr.io/casebender/workflow-processor:latest docker push casebenderacr.azurecr.io/casebender/misp-processor:latest ``` ## Step 4: Deploy Services ### Create Container Apps Environment ```bash theme={null} # Create Container Apps environment az containerapp env create \ --name casebender-env \ --resource-group $RESOURCE_GROUP \ --location $LOCATION # Create main application az containerapp create \ --name casebender-app \ --resource-group $RESOURCE_GROUP \ --environment casebender-env \ --image casebenderacr.azurecr.io/casebender/app:latest \ --target-port 3000 \ --ingress external \ --registry-server casebenderacr.azurecr.io \ --registry-username $ACR_USERNAME \ --registry-password $ACR_PASSWORD \ --user-assigned-identity $IDENTITY_ID \ --env-vars \ AUTH_SECRET= \ AUTH_SALT= \ POSTGRES_PRISMA_URL="postgresql://superadmin:@casebender-db.postgres.database.azure.com:5432/casebender" \ REDIS_URL="redis://casebender-redis.redis.cache.windows.net:6380?ssl=true&password=" \ AZURE_STORAGE_ACCOUNT="casebenderstorage" \ AZURE_STORAGE_CONTAINER="casebender" \ AZURE_STORAGE_CONNECTION_STRING="DefaultEndpointsProtocol=https;AccountName=casebenderstorage;AccountKey=${STORAGE_KEY};EndpointSuffix=core.windows.net" # Create workflow processor az containerapp create \ --name workflow-processor \ --resource-group $RESOURCE_GROUP \ --environment casebender-env \ --image casebenderacr.azurecr.io/casebender/workflow-processor:latest \ --registry-server casebenderacr.azurecr.io \ --registry-username $ACR_USERNAME \ --registry-password $ACR_PASSWORD \ --min-replicas 1 \ --max-replicas 1 \ --env-vars \ POSTGRES_PRISMA_URL="postgresql://superadmin:@casebender-db.postgres.database.azure.com:5432/casebender" \ REDIS_URL="redis://casebender-redis.redis.cache.windows.net:6380?ssl=true&password=" # Create MISP processor az containerapp create \ --name misp-processor \ --resource-group $RESOURCE_GROUP \ --environment casebender-env \ --image casebenderacr.azurecr.io/casebender/misp-processor:latest \ --registry-server casebenderacr.azurecr.io \ --registry-username $ACR_USERNAME \ --registry-password $ACR_PASSWORD \ --min-replicas 1 \ --max-replicas 1 \ --env-vars \ POSTGRES_PRISMA_URL="postgresql://superadmin:@casebender-db.postgres.database.azure.com:5432/casebender" \ REDIS_URL="redis://casebender-redis.redis.cache.windows.net:6380?ssl=true&password=" ``` ## Step 5: Set Up Azure Front Door ```bash theme={null} # Create Front Door profile az afd profile create \ --profile-name casebender-afd \ --resource-group $RESOURCE_GROUP \ --sku Standard_AzureFrontDoor # Create endpoint az afd endpoint create \ --endpoint-name casebender \ --profile-name casebender-afd \ --resource-group $RESOURCE_GROUP # Create origin group az afd origin-group create \ --origin-group-name casebender-origin-group \ --profile-name casebender-afd \ --resource-group $RESOURCE_GROUP \ --probe-path "/" \ --probe-protocol Http \ --probe-request-type GET # Add origin az afd origin create \ --origin-group-name casebender-origin-group \ --origin-name casebender-origin \ --profile-name casebender-afd \ --resource-group $RESOURCE_GROUP \ --host-name \ --origin-host-header \ --priority 1 \ --weight 1000 \ --enabled-state Enabled ``` ## Step 6: Configure Custom Domain (Optional) ```bash theme={null} # Add custom domain to Front Door az afd custom-domain create \ --custom-domain-name casebender-domain \ --host-name your-domain.com \ --profile-name casebender-afd \ --resource-group $RESOURCE_GROUP \ --minimum-tls-version TLS12 # Enable HTTPS az afd custom-domain enable-https \ --custom-domain-name casebender-domain \ --profile-name casebender-afd \ --resource-group $RESOURCE_GROUP ``` ## Monitoring and Maintenance ### Set Up Application Insights ```bash theme={null} # Create Application Insights az monitor app-insights component create \ --app casebender-insights \ --location $LOCATION \ --resource-group $RESOURCE_GROUP \ --application-type web # Get instrumentation key az monitor app-insights component show \ --app casebender-insights \ --resource-group $RESOURCE_GROUP \ --query instrumentationKey \ --output tsv ``` ### Configure Alerts ```bash theme={null} # Create action group az monitor action-group create \ --name casebender-alerts \ --resource-group $RESOURCE_GROUP \ --action email admin email@yourdomain.com # Create alert rule az monitor metrics alert create \ --name "high-cpu-usage" \ --resource-group $RESOURCE_GROUP \ --scopes \ --condition "avg CPU > 80" \ --window-size 5m \ --evaluation-frequency 1m \ --action ``` ### View Logs ```bash theme={null} # View container app logs az containerapp logs show \ --name casebender-app \ --resource-group $RESOURCE_GROUP \ --follow ``` ## Scaling Configuration ```bash theme={null} # Configure scaling rules az containerapp update \ --name casebender-app \ --resource-group $RESOURCE_GROUP \ --min-replicas 1 \ --max-replicas 10 \ --scale-rule-name http-rule \ --scale-rule-type http \ --scale-rule-http-concurrency 50 ``` ## Backup and Disaster Recovery ### Configure Database Backups ```bash theme={null} # Enable automated backups az postgres flexible-server update \ --resource-group $RESOURCE_GROUP \ --name casebender-db \ --backup-retention 7 ``` ### Configure Geo-Replication ```bash theme={null} # Create secondary region resources az postgres flexible-server replica create \ --name casebender-db-secondary \ --source-server casebender-db \ --resource-group $RESOURCE_GROUP \ --location westus ``` ## Security Best Practices 1. Enable Azure Defender for all services 2. Implement Azure Private Link 3. Use Managed Identities 4. Regular security assessments 5. Enable diagnostic logging ## Cost Optimization 1. Use consumption plan for Container Apps 2. Implement auto-scaling rules 3. Choose appropriate service tiers 4. Monitor usage patterns 5. Use Azure Reserved Instances ## Next Steps * Set up CI/CD with Azure DevOps * Implement comprehensive monitoring * Configure disaster recovery * Review security compliance # Desktop Installer Source: https://docs.casebender.com/en/deployment/desktop-installer One-click installer for deploying CaseBender locally The CaseBender Desktop Installer is the easiest way to deploy CaseBender on your local machine. It handles Docker setup, configuration, and service management automatically. ## Download Installer The installer automatically detects your system and configures CaseBender with optimal settings. **For Apple Silicon (M1/M2/M3) and Intel Macs** Recommended for M1/M2/M3 Macs For Intel-based Macs **Installation:** 1. Download the DMG file for your Mac 2. Open the DMG and drag CaseBender Installer to Applications 3. Launch from Applications folder 4. If prompted about unidentified developer, right-click and select "Open" **For Windows 10/11 (64-bit)** Recommended installer with auto-updates No installation required **Installation:** 1. Download the installer 2. Run the installer (you may need to click "More info" → "Run anyway" if Windows SmartScreen appears) 3. Follow the installation wizard 4. Launch CaseBender Installer from the Start menu **For Ubuntu, Debian, and other distributions** Works on most Linux distributions For Debian/Ubuntu-based systems **Installation (AppImage):** ```bash theme={null} chmod +x CaseBender-Installer.AppImage ./CaseBender-Installer.AppImage ``` **Installation (DEB):** ```bash theme={null} sudo dpkg -i CaseBender-Installer.deb sudo apt-get install -f # Install dependencies if needed ``` ## System Requirements | Component | Minimum | Recommended | | -------------- | ---------------------------------------- | ----------- | | **RAM** | 8 GB | 16 GB | | **Disk Space** | 10 GB | 20 GB | | **Docker** | 20.10+ | Latest | | **OS** | macOS 10.15+, Windows 10+, Ubuntu 20.04+ | Latest LTS | Docker Desktop must be installed and running before using the CaseBender Installer. The installer will guide you through Docker installation if it's not detected. ## Features Deploy CaseBender with a single click. No command line required. Automatically generates secure credentials and SSL certificates. Start, stop, and monitor all CaseBender services from a unified dashboard. Update to the latest version with one click. ## What Gets Installed The installer deploys the following services: * **CaseBender Web App** - Main application (port 3000) * **PostgreSQL** - Database (port 5433) * **Redis** - Cache and message queue (port 6379) * **Workflow Processor** - Background job processing (port 3001) * **MISP Processor** - Threat intelligence integration (port 3002) * **MinIO** - Object storage for attachments (ports 9000, 9090) * **Nginx** - SSL termination and reverse proxy (ports 80, 443) ## First Launch After installation: 1. **Start Docker Desktop** - Ensure Docker is running 2. **Launch the Installer** - Open CaseBender Installer 3. **Click "Install"** - The installer will pull images and configure services 4. **Access CaseBender** - Open `https://local.casebender.com` in your browser ## Default Credentials ``` Username: admin@casebender.app Password: secret1234 ``` Change these credentials immediately after your first login for security. ## Troubleshooting ### Docker Not Found If the installer can't find Docker: 1. Install [Docker Desktop](https://www.docker.com/products/docker-desktop/) 2. Start Docker Desktop 3. Wait for Docker to fully initialize (green icon in system tray) 4. Restart the CaseBender Installer ### Port Conflicts If you see port conflict errors: 1. Check which application is using the port: `lsof -i :PORT` (macOS/Linux) or `netstat -ano | findstr :PORT` (Windows) 2. Stop the conflicting application 3. Retry the installation ### macOS Gatekeeper Warning If macOS blocks the app: 1. Right-click (or Control+click) on the app 2. Select "Open" from the context menu 3. Click "Open" in the dialog ### Windows SmartScreen If Windows blocks the installer: 1. Click "More info" 2. Click "Run anyway" ## Manual Installation If you prefer manual installation or need more control, see the [Quickstart Guide](/en/quickstart) for Docker Compose setup instructions. ## All Releases View all available versions and release notes on our [GitHub Releases](https://github.com/casebender/casebender/releases) page. # Deploy to DigitalOcean Source: https://docs.casebender.com/en/deployment/digitalocean Deploy CaseBender on DigitalOcean ## Overview This guide walks you through deploying CaseBender on DigitalOcean using pre-built Docker images with Kubernetes (DOKS) and managed services. ## Prerequisites 1. [DigitalOcean Account](https://cloud.digitalocean.com/) 2. [doctl](https://docs.digitalocean.com/reference/doctl/how-to/install/) CLI installed 3. [kubectl](https://kubernetes.io/docs/tasks/tools/) installed 4. [Docker](https://docs.docker.com/get-docker/) installed ## Step 1: Initial Setup ### Install and Configure doctl ```bash macOS theme={null} # Using Homebrew brew install doctl # Authenticate with API token doctl auth init # Configure Docker for Container Registry doctl registry login ``` ```bash Linux theme={null} # Download latest release cd ~/Downloads wget https://github.com/digitalocean/doctl/releases/download/v1.XX.X/doctl-1.XX.X-linux-amd64.tar.gz # Extract and move to path tar xf ~/Downloads/doctl-1.XX.X-linux-amd64.tar.gz sudo mv ~/Downloads/doctl /usr/local/bin # Authenticate with API token doctl auth init # Configure Docker for Container Registry doctl registry login ``` ```powershell Windows theme={null} # Using Chocolatey choco install doctl # Authenticate with API token doctl auth init # Configure Docker for Container Registry doctl registry login ``` ## Step 2: Create Kubernetes Cluster ```bash theme={null} # Create DOKS cluster doctl kubernetes cluster create casebender \ --region nyc1 \ --size s-2vcpu-4gb \ --count 3 \ --version latest # Get kubeconfig doctl kubernetes cluster kubeconfig save casebender ``` ## Step 3: Set Up Managed Services ### Create Spaces for Object Storage ```bash theme={null} # Create Spaces bucket doctl spaces create casebender-storage \ --region nyc3 # Create Spaces access key doctl spaces access-key create # Note: Save the access key and secret key securely # They will be needed for application configuration ``` ### Create Managed PostgreSQL ```bash theme={null} # Create database cluster doctl databases create \ --engine pg \ --name casebender-db \ --region nyc1 \ --size db-s-2vcpu-4gb \ --version 14 \ --num-nodes 1 # Create database doctl databases db create casebender-db casebender # Get connection details doctl databases connection casebender-db --format ConnectionString ``` ### Create Managed Redis ```bash theme={null} # Create Redis cluster doctl databases create \ --engine redis \ --name casebender-redis \ --region nyc1 \ --size db-s-1vcpu-2gb \ --version 7 # Get connection details doctl databases connection casebender-redis --format ConnectionString ``` ## Step 4: Configure Container Registry ```bash theme={null} # Create container registry doctl registry create casebender-registry # Get registry endpoint REGISTRY_ENDPOINT=$(doctl registry get-endpoint) # Pull CaseBender images docker pull casebender/casebender:latest docker pull casebender/workflow-processor:latest docker pull casebender/misp-processor:latest # Tag images for registry docker tag casebender/casebender:latest registry.digitalocean.com/casebender-registry/app:latest docker tag casebender/workflow-processor:latest registry.digitalocean.com/casebender-registry/workflow-processor:latest docker tag casebender/misp-processor:latest registry.digitalocean.com/casebender-registry/misp-processor:latest # Push images docker push registry.digitalocean.com/casebender-registry/app:latest docker push registry.digitalocean.com/casebender-registry/workflow-processor:latest docker push registry.digitalocean.com/casebender-registry/misp-processor:latest # Add registry to Kubernetes cluster doctl kubernetes cluster registry add casebender ``` ## Step 5: Deploy to Kubernetes ### Create Namespace ```bash theme={null} kubectl create namespace casebender ``` ### Create Secrets ```bash theme={null} # Create secrets for database and Redis kubectl create secret generic db-credentials \ --namespace casebender \ --from-literal=postgres-url="postgresql://doadmin:password@casebender-db-do-user-1234567-0.b.db.ondigitalocean.com:25060/casebender?sslmode=require" \ --from-literal=redis-url="rediss://default:password@casebender-redis-do-user-1234567-0.b.db.ondigitalocean.com:25061" # Create secrets for application kubectl create secret generic app-secrets \ --namespace casebender \ --from-literal=auth-secret="your-auth-secret" \ --from-literal=auth-salt="your-auth-salt" ``` ### Deploy Applications Create `deployment.yaml`: ```yaml theme={null} apiVersion: apps/v1 kind: Deployment metadata: name: casebender-app namespace: casebender spec: replicas: 2 selector: matchLabels: app: casebender-app template: metadata: labels: app: casebender-app spec: containers: - name: app image: registry.digitalocean.com/casebender-registry/app:latest ports: - containerPort: 3000 env: - name: AUTH_SECRET valueFrom: secretKeyRef: name: app-secrets key: auth-secret - name: AUTH_SALT valueFrom: secretKeyRef: name: app-secrets key: auth-salt - name: POSTGRES_PRISMA_URL valueFrom: secretKeyRef: name: db-credentials key: postgres-url - name: REDIS_URL valueFrom: secretKeyRef: name: db-credentials key: redis-url --- apiVersion: apps/v1 kind: Deployment metadata: name: workflow-processor namespace: casebender spec: replicas: 1 selector: matchLabels: app: workflow-processor template: metadata: labels: app: workflow-processor spec: containers: - name: processor image: registry.digitalocean.com/casebender-registry/workflow-processor:latest env: - name: POSTGRES_PRISMA_URL valueFrom: secretKeyRef: name: db-credentials key: postgres-url - name: REDIS_URL valueFrom: secretKeyRef: name: db-credentials key: redis-url --- apiVersion: apps/v1 kind: Deployment metadata: name: misp-processor namespace: casebender spec: replicas: 1 selector: matchLabels: app: misp-processor template: metadata: labels: app: misp-processor spec: containers: - name: processor image: registry.digitalocean.com/casebender-registry/misp-processor:latest env: - name: POSTGRES_PRISMA_URL valueFrom: secretKeyRef: name: db-credentials key: postgres-url - name: REDIS_URL valueFrom: secretKeyRef: name: db-credentials key: redis-url ``` Apply the deployments: ```bash theme={null} kubectl apply -f deployment.yaml ``` ### Create Services Create `service.yaml`: ```yaml theme={null} apiVersion: v1 kind: Service metadata: name: casebender-app namespace: casebender spec: type: ClusterIP ports: - port: 80 targetPort: 3000 selector: app: casebender-app ``` Apply the service: ```bash theme={null} kubectl apply -f service.yaml ``` ## Step 7: Set Up Ingress ### Install NGINX Ingress Controller ```bash theme={null} # Add Helm repository helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx helm repo update # Install NGINX Ingress Controller helm install nginx-ingress ingress-nginx/ingress-nginx \ --namespace casebender \ --set controller.publishService.enabled=true ``` ### Configure Ingress Create `ingress.yaml`: ```yaml theme={null} apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: casebender-ingress namespace: casebender annotations: kubernetes.io/ingress.class: nginx cert-manager.io/cluster-issuer: letsencrypt-prod spec: tls: - hosts: - your-domain.com secretName: casebender-tls rules: - host: your-domain.com http: paths: - path: / pathType: Prefix backend: service: name: casebender-app port: number: 80 ``` Apply the ingress: ```bash theme={null} kubectl apply -f ingress.yaml ``` ## Step 8: Set Up SSL with cert-manager ```bash theme={null} # Install cert-manager kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.8.0/cert-manager.yaml # Create ClusterIssuer cat < ```bash macOS theme={null} # Using Homebrew brew install google-cloud-sdk # Login to Google Cloud gcloud auth login # Configure Docker to use Google Cloud gcloud auth configure-docker ``` ```bash Linux theme={null} # Download the archive curl -O https://dl.google.com/dl/cloudsdk/channels/rapid/downloads/google-cloud-cli-VERSION-linux-x86_64.tar.gz # Extract the archive tar -xf google-cloud-cli-VERSION-linux-x86_64.tar.gz # Run the install script ./google-cloud-sdk/install.sh # Login to Google Cloud gcloud auth login # Configure Docker to use Google Cloud gcloud auth configure-docker ``` ```powershell Windows theme={null} # Download and run the installer # https://dl.google.com/dl/cloudsdk/channels/rapid/GoogleCloudSDKInstaller.exe # Login to Google Cloud gcloud auth login # Configure Docker to use Google Cloud gcloud auth configure-docker ``` ### Initialize Project ```bash theme={null} # Set your project ID gcloud config set project YOUR_PROJECT_ID # Enable required APIs gcloud services enable \ cloudbuild.googleapis.com \ run.googleapis.com \ secretmanager.googleapis.com \ cloudresourcemanager.googleapis.com \ artifactregistry.googleapis.com ``` ## Step 2: Set Up Cloud Infrastructure ### Create Cloud Storage Bucket ```bash theme={null} # Create storage bucket gsutil mb -l us-central1 gs://casebender-storage # Create service account for storage gcloud iam service-accounts create casebender-storage \ --display-name "CaseBender Storage Service Account" # Get the service account email STORAGE_SA_EMAIL=$(gcloud iam service-accounts list \ --filter="displayName:CaseBender Storage Service Account" \ --format="value(email)") # Grant permissions gsutil iam ch \ serviceAccount:$STORAGE_SA_EMAIL:objectViewer,objectCreator \ gs://casebender-storage # Create and download service account key gcloud iam service-accounts keys create storage-key.json \ --iam-account=$STORAGE_SA_EMAIL # Create secret for storage credentials gcloud secrets create casebender-storage-key \ --replication-policy="automatic" # Import the service account key as a secret gcloud secrets versions add casebender-storage-key \ --data-file=storage-key.json ``` ### Set Up Cloud SQL (PostgreSQL) ```bash theme={null} # Create PostgreSQL instance gcloud sql instances create casebender-db \ --database-version=POSTGRES_14 \ --cpu=2 \ --memory=4GB \ --region=us-central1 \ --root-password="YOUR_SECURE_PASSWORD" # Create database gcloud sql databases create casebender \ --instance=casebender-db # Create user gcloud sql users create casebender \ --instance=casebender-db \ --password="YOUR_SECURE_PASSWORD" ``` ### Set Up Memorystore (Redis) ```bash theme={null} # Create Redis instance gcloud redis instances create casebender-redis \ --size=2 \ --region=us-central1 \ --redis-version=redis_6_x ``` ### Configure Secret Manager ```bash theme={null} # Create and store environment variables cat << EOF | gcloud secrets create casebender-env --data-file=- AUTH_SECRET=your-auth-secret AUTH_SALT=your-auth-salt POSTGRES_PRISMA_URL="postgresql://casebender:YOUR_SECURE_PASSWORD@/casebender?host=/cloudsql/YOUR_PROJECT_ID:us-central1:casebender-db" REDIS_URL="redis://REDIS_IP_ADDRESS:6379" GOOGLE_STORAGE_BUCKET=casebender-storage EOF ``` ## Step 3: Pull and Push Docker Images ```bash theme={null} # Create Artifact Registry repository gcloud artifacts repositories create casebender \ --repository-format=docker \ --location=us-central1 # Configure Docker for Artifact Registry gcloud auth configure-docker us-central1-docker.pkg.dev # Pull CaseBender images docker pull casebender/casebender:latest docker pull casebender/workflow-processor:latest docker pull casebender/misp-processor:latest # Tag images for Google Artifact Registry docker tag casebender/casebender:latest us-central1-docker.pkg.dev/$PROJECT_ID/casebender/app:latest docker tag casebender/workflow-processor:latest us-central1-docker.pkg.dev/$PROJECT_ID/casebender/workflow-processor:latest docker tag casebender/misp-processor:latest us-central1-docker.pkg.dev/$PROJECT_ID/casebender/misp-processor:latest # Push images docker push us-central1-docker.pkg.dev/$PROJECT_ID/casebender/app:latest docker push us-central1-docker.pkg.dev/$PROJECT_ID/casebender/workflow-processor:latest docker push us-central1-docker.pkg.dev/$PROJECT_ID/casebender/misp-processor:latest ``` ## Step 4: Deploy Services ### Deploy Main Application ```bash theme={null} # Deploy to Cloud Run gcloud run deploy casebender \ --image us-central1-docker.pkg.dev/$PROJECT_ID/casebender/app:latest \ --platform managed \ --region us-central1 \ --allow-unauthenticated \ --set-env-vars GOOGLE_STORAGE_BUCKET=casebender-storage \ --set-secrets "/secrets/storage-key=casebender-storage-key:latest" \ --service-account=$STORAGE_SA_EMAIL \ --add-cloudsql-instances $PROJECT_ID:us-central1:casebender-db \ --set-secrets "/app/.env=casebender-env:latest" ``` ### Deploy Workflow Processor ```bash theme={null} # Deploy workflow processor gcloud run deploy workflow-processor \ --image us-central1-docker.pkg.dev/$PROJECT_ID/casebender/workflow-processor:latest \ --platform managed \ --region us-central1 \ --no-allow-unauthenticated \ --service-account=$STORAGE_SA_EMAIL \ --add-cloudsql-instances $PROJECT_ID:us-central1:casebender-db \ --set-secrets "/app/.env=casebender-env:latest" ``` ### Deploy MISP Processor ```bash theme={null} # Deploy MISP processor gcloud run deploy misp-processor \ --image us-central1-docker.pkg.dev/$PROJECT_ID/casebender/misp-processor:latest \ --platform managed \ --region us-central1 \ --no-allow-unauthenticated \ --service-account=$STORAGE_SA_EMAIL \ --add-cloudsql-instances $PROJECT_ID:us-central1:casebender-db \ --set-secrets "/app/.env=casebender-env:latest" ``` ## Step 5: Configure Domain and SSL ### Map Custom Domain ```bash theme={null} # Add domain mapping gcloud run domain-mappings create \ --service casebender \ --domain your-domain.com \ --region us-central1 ``` Follow the DNS verification steps in the Google Cloud Console to complete domain mapping. ## Monitoring and Maintenance ### Set Up Monitoring 1. Navigate to Cloud Monitoring in Google Cloud Console 2. Create an uptime check for your service 3. Set up alerts for: * Error rates * Latency * Instance count * Memory usage ### View Logs ```bash theme={null} # View service logs gcloud logging read "resource.type=cloud_run_revision AND resource.labels.service_name=casebender" --limit 50 # Stream logs gcloud logging tail "resource.type=cloud_run_revision AND resource.labels.service_name=casebender" ``` ### Update Application To deploy updates: ```bash theme={null} # Build and deploy new version gcloud builds submit --config cloudbuild.yaml # Roll back if needed gcloud run services rollback casebender \ --to-revision=REVISION_ID \ --region=us-central1 ``` ## Cost Optimization 1. **Autoscaling Configuration** ```bash theme={null} gcloud run services update casebender \ --min-instances=1 \ --max-instances=10 \ --region=us-central1 ``` 2. **Resource Allocation** ```bash theme={null} gcloud run services update casebender \ --memory=1Gi \ --cpu=1 \ --region=us-central1 ``` ## Troubleshooting ### Common Issues 1. **Connection Issues** * Verify Cloud SQL connection * Check Redis connectivity * Validate environment variables 2. **Performance Problems** * Review instance metrics * Check resource allocation * Analyze request patterns 3. **Deployment Failures** * Check build logs * Verify service account permissions * Review deployment configuration ## Next Steps * Set up CI/CD pipelines * Configure backup strategies * Implement monitoring and alerting * Review security best practices # Deployment Overview Source: https://docs.casebender.com/en/deployment/overview Learn how to deploy CaseBender to various cloud platforms ## Deployment Options CaseBender can be deployed to various cloud platforms, each offering different advantages. Choose the platform that best suits your organization's needs: Serverless container platform with automatic scaling Deploy on Amazon's cloud infrastructure Microsoft's cloud platform with enterprise features Simple and cost-effective cloud platform ## Deployment Considerations Before deploying CaseBender to production, consider the following: ### Infrastructure Requirements * **CPU/Memory**: Minimum 2 vCPUs and 4GB RAM recommended * **Storage**: At least 20GB for the application and databases * **Network**: HTTPS required, with valid SSL certificate * **Database**: PostgreSQL 14+ instance * **Cache**: Redis 6+ instance ### Security Considerations 1. **SSL/TLS Configuration** * Always use HTTPS in production * Keep certificates up to date * Configure secure SSL parameters 2. **Network Security** * Set up proper firewalls * Use private networking where possible * Implement rate limiting 3. **Access Control** * Use strong authentication * Implement role-based access control * Regular security audits ### Monitoring and Maintenance 1. **Health Checks** * Set up application monitoring * Configure automated health checks * Implement logging and alerting 2. **Backup Strategy** * Regular database backups * Automated backup testing * Disaster recovery plan 3. **Updates and Maintenance** * Regular security updates * Scheduled maintenance windows * Version control strategy ## Deployment Checklist Before deploying to any platform, ensure you have: * [ ] Production-ready SSL certificates * [ ] Secure environment variables * [ ] Database backup strategy * [ ] Monitoring tools configured * [ ] Security measures implemented * [ ] Documentation for maintenance procedures ## Next Steps Choose your preferred deployment platform from the options above to get detailed, platform-specific deployment instructions. # Introduction Source: https://docs.casebender.com/en/introduction Welcome to CaseBender Documentation Hero Light Hero Dark ## Welcome to CaseBender CaseBender is a powerful case management and alert handling platform designed to streamline your security operations. Our platform helps teams efficiently manage, investigate, and respond to security alerts and cases. ## Key Features Efficiently handle and process security alerts with advanced filtering and automation Create and manage cases with comprehensive tracking and collaboration features Automate repetitive tasks and streamline your security operations Connect with your existing security tools and data sources Enterprise-grade security with 20+ controls and 10+ compliance frameworks ## Getting Started Get started with CaseBender by following our comprehensive guides: Get up and running with CaseBender in minutes Learn about the fundamental concepts of CaseBender # Quickstart Guide Source: https://docs.casebender.com/en/quickstart Deploy CaseBender locally in minutes **Looking for an easier way?** Use our [Desktop Installer](/en/deployment/desktop-installer) for one-click deployment with automatic configuration. No command line required! ## Prerequisites Before you begin, make sure you have the following installed on your system: * Docker Engine (20.10.0 or higher) * Docker Compose (v2.0.0 or higher) * OpenSSL (for generating SSL certificates) ### Installing Docker #### For macOS: 1. Download and install Docker Desktop from [Docker Hub](https://hub.docker.com/editions/community/docker-ce-desktop-mac) 2. Follow the installation wizard 3. Verify installation: ```bash theme={null} docker --version docker compose --version ``` #### For Linux (Ubuntu/Debian): ```bash theme={null} # Update package index sudo apt-get update # Install prerequisites sudo apt-get install \ apt-transport-https \ ca-certificates \ curl \ gnupg \ lsb-release # Add Docker's official GPG key curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg # Set up stable repository echo \ "deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu \ $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null # Install Docker Engine sudo apt-get update sudo apt-get install docker-ce docker-ce-cli containerd.io docker-compose-plugin # Add your user to docker group sudo usermod -aG docker $USER ``` #### For Windows: 1. Download and install Docker Desktop from [Docker Hub](https://hub.docker.com/editions/community/docker-ce-desktop-windows) 2. Enable WSL 2 following Docker's documentation 3. Follow the installation wizard 4. Verify installation in PowerShell: ```powershell theme={null} docker --version docker compose --version ``` ## Step 1: Create Project Directory Create a new directory for your CaseBender deployment and navigate into it: ```bash theme={null} mkdir casebender-deployment cd casebender-deployment ``` ## Step 2: Configure Environment Variables Create a `.env` file with the following content: ```bash theme={null} # Authentication AUTH_SECRET="B7OawnWf6+LwB/9yXbxbk4ppZ1khydqj4qc9k9g3nnE=" AUTH_SALT="B7OawnW" AUTH_TRUST_HOST=true NEXTAUTH_URL=https://local.casebender.com NEXTAPP_URL=https://local.casebender.com # License # On first boot the app auto-generates a Community license. Set a stable key so # your license survives restarts. Generate one with: openssl rand -hex 32 LICENSE_SECRET_KEY=replace-with-output-of-openssl-rand-hex-32 # Liveblocks Configuration (real-time collaboration) LIVEBLOCKS_SECRET_KEY=sk_dev_HaIczPV4gPit5_gx7YRsNXLGJNzBE5wQ8z8I1H8ft3ZPZHVrfH2ryJJ586ezHYla # Database Configuration (host is the internal "db" service) POSTGRES_PASSWORD=88AlwaysTimeToWin88 POSTGRES_PRISMA_URL="postgresql://superadmin:88AlwaysTimeToWin88@db:5432/casebender?schema=public" POSTGRES_URL="postgresql://superadmin:88AlwaysTimeToWin88@db:5432/casebender?schema=public" POSTGRES_URL_NON_POOLING="postgresql://superadmin:88AlwaysTimeToWin88@db:5432/casebender?schema=public" # Redis Configuration REDIS_URL="redis://redis:6379" ``` CaseBender runs as several containers: the **web app** (`app`), a **REST API gateway** (`api`), an **alert ingestion gateway** (`ingestion`, this is what receives integration webhooks such as Microsoft Defender), a background **worker**, and the **workflow** and **MISP** processors. Nginx sits in front and routes traffic to the right service. All of these are included in the Compose file below. ## Step 3: Generate SSL Certificates For local development, generate self-signed SSL certificates: ```bash theme={null} # Generate SSL certificate and key openssl req -x509 -nodes -days 365 -newkey rsa:2048 \ -keyout local-casebender.key \ -out local-casebender.crt \ -subj "/CN=local.casebender.com/O=CaseBender/C=US" # Verify the certificate openssl x509 -in local-casebender.crt -text -noout ``` ## Step 4: Configure Nginx Create `nginx.conf` with the following content: ```nginx theme={null} events { worker_connections 1024; } http { # ─── Upstreams ───────────────────────────────────────────── upstream web_app { server app:3000; } upstream api_service { server api:3005; } upstream ingestion_service { server ingestion:3003; } # ─── Rate Limiting ───────────────────────────────────────── limit_req_zone $binary_remote_addr zone=api_limit:10m rate=100r/s; limit_req_zone $binary_remote_addr zone=ingest_limit:10m rate=1000r/s; # ─── HTTP -> HTTPS Redirect ──────────────────────────────── server { listen 80; server_name local.casebender.com; return 301 https://$server_name$request_uri; } # ─── Main HTTPS Server ───────────────────────────────────── server { listen 443 ssl; http2 on; server_name local.casebender.com; ssl_certificate /etc/nginx/certs/local-casebender.crt; ssl_certificate_key /etc/nginx/certs/local-casebender.key; ssl_protocols TLSv1.2 TLSv1.3; client_max_body_size 100M; # ─── Security Headers ───────────────────────────────── add_header X-Frame-Options "SAMEORIGIN" always; add_header X-Content-Type-Options "nosniff" always; add_header X-XSS-Protection "1; mode=block" always; add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; # ─── Ingestion API (integration webhooks) ───────────── location /api/v1/ingest/ { limit_req zone=ingest_limit burst=500 nodelay; proxy_pass http://ingestion_service; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Legacy ingestion route location /api/ingest/ { limit_req zone=ingest_limit burst=500 nodelay; proxy_pass http://ingestion_service; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # ─── REST API Gateway ───────────────────────────────── location /api/v1/ { limit_req zone=api_limit burst=50 nodelay; proxy_pass http://api_service; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /api/openapi.json { proxy_pass http://api_service; proxy_set_header Host $host; } # ─── Health Check ───────────────────────────────────── location /health { access_log off; return 200 "healthy"; add_header Content-Type text/plain; } # ─── Web Application (catch-all) ────────────────────── location / { proxy_pass http://web_app; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Port $server_port; # WebSocket support proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_connect_timeout 60s; proxy_send_timeout 60s; proxy_read_timeout 60s; } } } ``` ## Step 5: Create Docker Compose Configuration Create `docker-compose.yml` with the following content: ```yaml theme={null} services: # ─── Core Services ─────────────────────────────────────────── app: image: casebender/casebender:latest platform: linux/amd64 ports: - "3000:3000" environment: - AUTH_SECRET=${AUTH_SECRET} - AUTH_SALT=${AUTH_SALT} - AUTH_TRUST_HOST=true - NEXTAUTH_URL=${NEXTAUTH_URL:-https://local.casebender.com} - NEXTAPP_URL=${NEXTAPP_URL:-https://local.casebender.com} - LICENSE_SECRET_KEY=${LICENSE_SECRET_KEY} - LIVEBLOCKS_SECRET_KEY=${LIVEBLOCKS_SECRET_KEY} - POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL} - POSTGRES_URL=${POSTGRES_URL} - POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING} - REDIS_URL=${REDIS_URL:-redis://redis:6379} depends_on: db: condition: service_healthy redis: condition: service_healthy restart: unless-stopped healthcheck: test: ["CMD-SHELL", "node -e \"require('http').get('http://localhost:3000/api/health', (r) => process.exit(r.statusCode === 200 ? 0 : 1)).on('error', () => process.exit(1))\""] interval: 10s timeout: 5s retries: 5 start_period: 60s api: image: casebender/api:latest platform: linux/amd64 ports: - "3005:3005" environment: - PORT=3005 - POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL} - POSTGRES_URL=${POSTGRES_URL} - POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING} - REDIS_URL=${REDIS_URL:-redis://redis:6379} - AUTH_SECRET=${AUTH_SECRET} depends_on: db: condition: service_healthy redis: condition: service_healthy restart: unless-stopped ingestion: image: casebender/ingestion:latest platform: linux/amd64 ports: - "3003:3003" environment: - PORT=3003 - POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL} - POSTGRES_URL=${POSTGRES_URL} - POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING} - REDIS_URL=${REDIS_URL:-redis://redis:6379} depends_on: db: condition: service_healthy redis: condition: service_healthy restart: unless-stopped # ─── Processing Services ───────────────────────────────────── worker: image: casebender/worker:latest platform: linux/amd64 ports: - "3002:3002" environment: - PORT=3002 - POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL} - POSTGRES_URL=${POSTGRES_URL} - POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING} - REDIS_URL=${REDIS_URL:-redis://redis:6379} depends_on: db: condition: service_healthy redis: condition: service_healthy restart: unless-stopped workflow-processor: image: casebender/workflow-processor:latest platform: linux/amd64 ports: - "3001:3001" environment: - POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL} - POSTGRES_URL=${POSTGRES_URL} - POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING} - REDIS_URL=${REDIS_URL:-redis://redis:6379} depends_on: db: condition: service_healthy redis: condition: service_healthy app: condition: service_healthy restart: unless-stopped misp-processor: image: casebender/misp-processor:latest platform: linux/amd64 ports: - "3004:3004" environment: - PORT=3004 - POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL} - POSTGRES_URL=${POSTGRES_URL} - POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING} - REDIS_URL=${REDIS_URL:-redis://redis:6379} depends_on: db: condition: service_healthy redis: condition: service_healthy app: condition: service_healthy restart: unless-stopped # ─── Infrastructure ────────────────────────────────────────── db: image: postgres:17 environment: POSTGRES_USER: superadmin POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-88AlwaysTimeToWin88} POSTGRES_DB: casebender ports: - "5433:5432" volumes: - pgdata:/var/lib/postgresql/data healthcheck: test: ["CMD-SHELL", "pg_isready -U superadmin -d casebender"] interval: 5s timeout: 5s retries: 10 start_period: 30s restart: unless-stopped redis: image: redis:7.2-alpine command: redis-server --protected-mode no ports: - "6379:6379" volumes: - redis_data:/data healthcheck: test: ["CMD", "redis-cli", "ping"] interval: 5s timeout: 3s retries: 5 restart: unless-stopped minio: image: quay.io/minio/minio mem_limit: 512m command: ["minio", "server", "/data", "--console-address", ":9090"] environment: - MINIO_ROOT_USER=minioadmin - MINIO_ROOT_PASSWORD=minioadmin ports: - "9090:9090" - "9000:9000" volumes: - "miniodata:/data" restart: unless-stopped # ─── Reverse Proxy ─────────────────────────────────────────── nginx: image: nginx:alpine ports: - "443:443" - "80:80" volumes: - ./nginx.conf:/etc/nginx/nginx.conf:ro - ./local-casebender.crt:/etc/nginx/certs/local-casebender.crt:ro - ./local-casebender.key:/etc/nginx/certs/local-casebender.key:ro depends_on: app: condition: service_healthy restart: unless-stopped volumes: miniodata: pgdata: redis_data: ``` Need enterprise search (OpenSearch)? The Desktop Installer can add the `search-sync`, `opensearch`, and `opensearch-dashboards` services for you. For most local evaluations the default PostgreSQL-based search above is all you need. ## Step 6: Configure Local DNS Add the following entry to your hosts file: ### For macOS and Linux: ```bash theme={null} sudo echo "127.0.0.1 local.casebender.com" >> /etc/hosts ``` ### For Windows: Add the following line to `C:\Windows\System32\drivers\etc\hosts`: ``` 127.0.0.1 local.casebender.com ``` ## Step 7: Start the Application 1. Pull the required images: ```bash theme={null} docker compose pull ``` 2. Start all services: ```bash theme={null} docker compose up -d ``` 3. Monitor the logs: ```bash theme={null} docker compose logs -f ``` 4. Access the application at `https://local.casebender.com` ## Default Login Credentials After deploying CaseBender, you can log in with the following default credentials: ``` Username: admin@casebender.app Password: secret1234 ``` For security reasons, we strongly recommend changing these default credentials immediately after your first login. ## Troubleshooting ### Common Issues 1. **Certificate Warnings**: * The browser will show a security warning because we're using a self-signed certificate * Click "Advanced" and proceed to the website * For development purposes, this is expected and safe 2. **Port Conflicts**: * Ensure ports 80, 443, 3000, 3001, 3002, 3003, 3004, 3005, 5433, 6379, 9000, and 9090 are not in use * If needed, modify the port mappings in docker-compose.yml 3. **Database Connection**: * Check PostgreSQL logs: `docker compose logs db` * Verify database credentials in .env * Ensure the database is running: `docker compose ps db` 4. **Service Dependencies**: * If services fail to start, check their dependencies: ```bash theme={null} docker compose ps docker compose logs [service_name] ``` ### Checking Logs View logs for specific services: ```bash theme={null} # All services docker compose logs # Specific service docker compose logs [service_name] # Follow logs docker compose logs -f [service_name] ``` ### Service Management ```bash theme={null} # Restart a specific service docker compose restart [service_name] # Stop all services docker compose down # Remove volumes (will delete all data) docker compose down -v ``` ## Next Steps Now that you have CaseBender running locally, you might want to: Deploy CaseBender to your production environment Learn about advanced configuration options # Access Control Source: https://docs.casebender.com/en/security/access-control Role-based access control, privileged access management, cross-team visibility, and API security in CaseBender. ## Role-Based Access Control (RBAC) CaseBender implements granular RBAC that controls access at every level of the platform. ### Role Hierarchy | Role | Scope | Capabilities | | --------------- | -------------- | -------------------------------------------------------------------------------- | | **Super Admin** | Platform-wide | Full platform configuration, user management, security settings, all data access | | **Org Admin** | Organization | Organization settings, team management, integration configuration, all org data | | **Team Lead** | Team | Team case assignment, workload management, team-level reporting | | **Analyst** | Assigned work | Case/alert investigation, task completion, comment and observable management | | **Read-Only** | Assigned scope | View cases, alerts, and dashboards without modification capability | | **Integration** | API scope | Programmatic access scoped to specific API operations and data types | ### Permission Granularity Permissions are defined at the resource and action level: * **Entity Permissions**: Create, read, update, delete for cases, alerts, tasks, observables, comments * **Administrative Permissions**: User management, team management, organization settings * **Security Permissions**: RBAC configuration, audit log access, security settings * **Integration Permissions**: API key management, webhook configuration, external tool settings * **Compliance Permissions**: Retention policy management, legal hold, evidence collection ### TLP-Based Access Control In addition to RBAC, the Traffic Light Protocol restricts data visibility: * Users can only access entities at or below their maximum TLP clearance level * TLP restrictions are enforced at the database query level (not just UI) * TLP access checks are logged in the audit trail * TLP violations generate security alerts ## Privileged Access Management (PAM) CaseBender implements just-in-time privilege elevation for sensitive operations, ensuring no user has standing privileged access. ### How PAM Works 1. **Request**: User requests elevated privileges for a specific operation 2. **Justification**: User provides a business justification for the elevation 3. **Approval**: Request is routed to an approver (configurable per operation type) 4. **Time-Bound Grant**: Privileges are granted for a limited duration (default: 1 hour) 5. **Audit**: All actions performed during the elevated session are logged with the elevation context 6. **Auto-Revoke**: Privileges are automatically revoked when the time window expires ### Privileged Operations | Operation | Default Duration | Approval Required | | ------------------------------ | ---------------- | ----------------- | | Bulk data deletion | 30 minutes | Yes | | Security configuration changes | 1 hour | Yes | | User role elevation | 1 hour | Yes | | Audit log export | 30 minutes | No (logged) | | Integration credential access | 15 minutes | Yes | | Data retention policy changes | 1 hour | Yes | ### PAM Security Features * **No Standing Privileges**: Elevated access is always temporary * **Anomaly Detection**: Unusual elevation patterns trigger security alerts * **Session Recording**: All actions during elevated sessions are captured in detail * **Dual Approval**: Critical operations can require approval from two separate approvers * **Emergency Access**: Break-glass procedures for critical incidents with enhanced audit logging ## Cross-Team Case Visibility CaseBender supports controlled sharing of cases across team boundaries without compromising data isolation. ### Access Grant Types | Grant Type | Description | Use Case | | ---------------- | ----------------------------------------------- | -------------------------------- | | **Direct** | Specific user granted access to a specific case | Cross-functional investigation | | **Team** | Entire team granted access to a case | Escalation to specialized team | | **Organization** | All users in an organization can view the case | Major incident with broad impact | | **Temporary** | Time-limited access that auto-expires | External consultant review | ### Access Levels * **View**: Read case details, alerts, tasks, and timeline * **Comment**: View access plus ability to add comments and notes * **Contribute**: Comment access plus ability to add observables, tasks, and evidence * **Full**: Complete access including status changes and case management ## API Security ### API Key Management * **Scoped Keys**: Each API key is restricted to specific operations (read-only, write, admin) * **Tier-Based Limits**: Standard, Professional, and Enterprise tiers with different rate limits * **Key Rotation**: API keys can be rotated without downtime (grace period for old key) * **Expiration**: Optional expiration dates for temporary integrations * **Usage Tracking**: Per-key usage statistics and anomaly detection ### Rate Limiting | Tier | Requests/Minute | Burst Limit | Concurrent | | ---------------- | --------------- | ----------- | ---------- | | **Standard** | 60 | 100 | 5 | | **Professional** | 300 | 500 | 20 | | **Enterprise** | 1,000 | 2,000 | 50 | Rate limit headers are included in every API response: ``` X-RateLimit-Limit: 300 X-RateLimit-Remaining: 287 X-RateLimit-Reset: 1706745600 ``` ### Webhook Security * **HMAC Signatures**: Every webhook delivery is signed with HMAC-SHA256 * **Signature Verification**: Recipients can verify the signature to ensure authenticity * **Retry Logic**: Failed deliveries are retried with exponential backoff * **Delivery Logs**: Full delivery history with request/response details * **IP Allowlisting**: Optional restriction of webhook destinations to approved IP ranges ### Input Validation All API inputs are validated before processing: * **Schema Validation**: Zod schemas enforce type safety on every endpoint * **HTML Sanitization**: User-provided HTML is sanitized to prevent XSS * **SQL Injection Prevention**: Parameterized queries via Prisma ORM (no raw SQL) * **SSRF Prevention**: External URL validation blocks private IP ranges and internal hostnames * **File Upload Validation**: MIME type verification, extension blocking, size limits ## Related Documentation * [Authentication](/en/security/authentication) — MFA, SSO, and session management * [Threat Detection](/en/security/behavioral-analytics) — UEBA and insider threat monitoring * [Audit Logging](/en/security/audit-logging) — Access event logging # Security Architecture Source: https://docs.casebender.com/en/security/architecture CaseBender's Zero Trust architecture, service isolation, network segmentation, and multi-tenant security design. ## Zero Trust Architecture CaseBender implements a Zero Trust security model aligned with NIST SP 800-207. No service, user, or device is implicitly trusted regardless of network location. ### Core Principles 1. **Verify Explicitly**: Every request is authenticated and authorized based on all available data points — identity, device health, location, service identity, and data classification 2. **Least Privilege Access**: Users and services receive the minimum permissions required for their function, with just-in-time elevation for privileged operations 3. **Assume Breach**: The architecture assumes any component can be compromised and limits blast radius through segmentation and isolation ### Device Trust Assessment Every client device connecting to CaseBender is assessed for trust level: | Trust Level | Criteria | Access Granted | | ------------- | ------------------------------------------------------------------ | -------------------------------------------------- | | **Full** | Managed device, up-to-date OS, EDR active, compliant configuration | All operations including sensitive data | | **Elevated** | Known device, recent OS, security software present | Standard operations, restricted sensitive data | | **Standard** | Authenticated user, basic device info available | Read operations, limited write access | | **Reduced** | Unknown device or outdated security posture | Read-only access, step-up required for any changes | | **Untrusted** | Failed device checks or suspicious indicators | Access denied, security alert generated | ### Mutual Service Authentication Microservices within CaseBender authenticate to each other using HMAC-based mutual authentication: * Each service has a unique identity and signing key * Every inter-service request includes a cryptographic signature * Receiving services verify the signature before processing * Replay attacks are prevented with timestamp-based nonce validation * Key rotation is automated and does not require service restarts ### Step-Up Authentication Sensitive operations require re-authentication regardless of existing session validity: * **Bulk operations**: Deleting or modifying more than 10 entities * **Configuration changes**: Security settings, integration credentials, RBAC policies * **Privileged access**: PAM elevation requests, role assignments * **Data export**: Bulk data exports, audit log downloads * **Administrative actions**: User management, organization settings ## Service Architecture CaseBender is composed of isolated microservices, each with a single responsibility: ### Service Inventory | Service | Purpose | Exposed Ports | External Access | | ---------------------- | --------------------------------------------------- | ------------- | ----------------------- | | **web** | Next.js application server, UI, and tRPC API | 3000 | Yes (via reverse proxy) | | **api** | RESTful API for external integrations | 4000 | Yes (via reverse proxy) | | **worker** | Background job processing (alerts, enrichment, SLA) | None | No | | **ingestion** | Alert ingestion from external sources | 4100 | Yes (via reverse proxy) | | **workflow-processor** | Playbook and workflow execution | None | No | | **misp-processor** | MISP threat intelligence processing | None | No | | **search-sync** | Elasticsearch synchronization | None | No | ### Service Isolation * Each service runs in its own container with a dedicated non-root user * Services that do not need external access have no exposed ports * Inter-service communication uses authenticated internal channels * Each service has its own resource limits (CPU, memory) * Container images use minimal Alpine Linux base images to reduce attack surface ## Network Security ### Segmentation CaseBender's network architecture separates concerns into distinct zones: * **Public Zone**: Reverse proxy / load balancer (the only externally accessible component) * **Application Zone**: Web, API, and ingestion services (accessible only from public zone) * **Processing Zone**: Worker, workflow-processor, misp-processor, search-sync (no external access) * **Data Zone**: PostgreSQL, Redis, Elasticsearch (accessible only from application and processing zones) ### Communication Security * All external traffic requires TLS 1.3 (TLS 1.2 minimum with strong cipher suites) * Inter-service communication uses mutual TLS or HMAC authentication * Database connections are encrypted with SSL certificates * Redis connections use AUTH and TLS * Elasticsearch connections use API key authentication over TLS ### Rate Limiting CaseBender implements multi-layer rate limiting: * **Global**: Protects the entire platform from volumetric attacks * **Per-API-Key**: Tier-based limits (Standard, Professional, Enterprise) * **Per-Endpoint**: Sensitive endpoints (login, password reset) have stricter limits * **Sliding Window**: Prevents burst attacks while allowing legitimate traffic patterns ## Multi-Tenant Security ### Tenant Isolation CaseBender supports multi-tenant deployments with strict data isolation: * **Database-Level**: Every query is scoped to the tenant's `organizationId` — there is no way to query across tenants * **Application-Level**: Middleware enforces tenant context on every request before it reaches business logic * **API-Level**: API keys are scoped to a specific tenant and cannot access other tenants' data * **Search-Level**: Elasticsearch indices are tenant-scoped with filtered aliases ### TLP Classification The Traffic Light Protocol (TLP) provides an additional layer of data access control: | TLP Level | Visibility | Use Case | | -------------------- | ------------------------------------- | --------------------------------------------------- | | **TLP:RED** | Named recipients only | Active incident details, threat actor attribution | | **TLP:AMBER+STRICT** | Organization only, restricted sharing | Vulnerability details, internal investigation notes | | **TLP:AMBER** | Organization and clients | Threat intelligence, remediation guidance | | **TLP:GREEN** | Community-wide | General security advisories, best practices | | **TLP:CLEAR** | Unrestricted | Public information, published CVEs | TLP classifications propagate automatically from cases to child entities (alerts, tasks, observables) and are enforced at the query level. ## Container Security ### Build-Time Hardening Every CaseBender container image follows security best practices: * **Multi-Stage Builds**: Build dependencies are not included in production images * **Non-Root Users**: All services run as dedicated non-root users * **Minimal Base Images**: Alpine Linux to minimize attack surface * **Pinned Dependencies**: All system packages and tools are version-pinned * **Frozen Lockfiles**: `pnpm install --frozen-lockfile` ensures reproducible builds * **No Secrets in Images**: All secrets are injected at runtime via environment variables or secrets providers ### Runtime Hardening * Read-only root filesystem (where supported) * Dropped Linux capabilities * Resource limits (CPU, memory, file descriptors) * Health check endpoints for orchestrator monitoring * Graceful shutdown handling for zero-downtime deployments ## Related Documentation * [Data Protection](/en/security/data-protection) — Encryption, classification, and secrets management * [Authentication](/en/security/authentication) — MFA, SSO, and session management * [Supply Chain Security](/en/security/supply-chain) — Container signing and build verification * [Hardening Guide](/en/security/hardening-guide) — Deployment hardening recommendations # Audit Logging Source: https://docs.casebender.com/en/security/audit-logging CaseBender's unified audit trail, integrity verification, SIEM forwarding, legal hold, and e-discovery support. ## Unified Audit Trail CaseBender maintains a comprehensive, tamper-evident audit trail that records every significant action across the platform. The audit system is designed to satisfy the most stringent compliance requirements (SOC2 CC7.2, ISO 27001 A.8.15, HIPAA 164.312(b), CMMC AU.L2-3.3.1). ### What's Logged Every audit entry captures: | Field | Description | | -------------------- | ------------------------------------------------------------------------ | | **Timestamp** | Precise UTC timestamp of the action | | **Actor** | Who performed the action (user, system, integration, or API key) | | **Action** | What was done (create, read, update, delete, export, authenticate, etc.) | | **Target** | What entity was affected (case, alert, task, user, configuration, etc.) | | **Changes** | Before and after values for modifications | | **Context** | IP address, user agent, session ID, tenant ID | | **Compliance Flags** | Which compliance frameworks this event satisfies | ### Event Categories | Category | Examples | | ------------------- | --------------------------------------------------------------------- | | **Entity Access** | Case viewed, alert accessed, evidence downloaded | | **Entity Changes** | Case updated, alert status changed, task assigned | | **Authentication** | Login, logout, MFA challenge, SSO assertion, lockout | | **Authorization** | Access granted, access denied, privilege elevated, role changed | | **System Events** | Service started, configuration changed, backup completed | | **Data Export** | Audit log exported, case data exported, report generated | | **Security Events** | Anomaly detected, threat indicator triggered, policy violation | | **Bulk Operations** | Bulk update, bulk delete, bulk assign (with individual item tracking) | ### Query and Search The audit trail supports powerful querying: * **Full-Text Search**: Search across all audit fields * **Filtered Views**: Filter by date range, actor, action type, entity type, and more * **Saved Filters**: Save commonly used filter combinations * **Export**: Export filtered results in PDF, CSV, or structured JSON * **Scheduled Reports**: Configure recurring audit reports delivered via email ## Audit Integrity ### Tamper-Evident Hash Chains CaseBender protects audit log integrity using cryptographic hash chains: * Each audit entry includes a SHA-256 hash of the previous entry * This creates an immutable chain — modifying any entry would break the chain * Integrity verification can detect tampering at any point in the chain * Verification can be performed on-demand or on a schedule ### Integrity Verification * **On-Demand Verification**: Administrators can verify audit log integrity at any time * **Scheduled Verification**: Automated integrity checks run on a configurable schedule * **Verification Report**: Detailed report showing chain integrity status, any gaps, and anomalies * **Alert on Tampering**: If integrity verification fails, a security alert is generated immediately Audit log integrity verification satisfies SEC Rule 17a-4 (WORM storage equivalent), SOC2 CC7.2 (system monitoring), and ISO 27001 A.8.15 (logging). ## SIEM Forwarding CaseBender forwards audit events to your existing SIEM in real-time for centralized security monitoring. ### Supported Destinations | Destination | Protocol | Formats | | ---------------------- | -------------------------- | --------------------- | | **Splunk** | HTTP Event Collector (HEC) | JSON, CEF | | **Elastic / ELK** | Elasticsearch API | JSON (ECS-compatible) | | **IBM QRadar** | Syslog (TCP/TLS) | LEEF | | **Microsoft Sentinel** | Log Analytics API | JSON | | **Generic Syslog** | Syslog (TCP/UDP/TLS) | CEF, LEEF, JSON | | **Custom Webhook** | HTTPS POST | JSON | ### Forwarding Features * **Multiple Destinations**: Forward to multiple SIEMs simultaneously * **Event Filtering**: Choose which event categories to forward * **Buffering**: Events are buffered during SIEM outages and delivered when connectivity is restored * **Retry Logic**: Failed deliveries are retried with exponential backoff * **TLS Encryption**: All forwarded events are encrypted in transit * **Health Monitoring**: Forwarding health is monitored with alerts on delivery failures ## Legal Hold CaseBender includes a legal hold system for litigation preservation: ### Legal Hold Management * **Hold Creation**: Create legal holds with scope, custodians, and preservation requirements * **Scope Definition**: Define what data is preserved (cases, alerts, evidence, communications) * **Custodian Management**: Track custodians (individuals responsible for preserving data) * **Evidence Preservation**: Entities under legal hold are exempt from automated retention/deletion * **Hold Release**: Release holds when litigation concludes, with full audit trail ### Legal Hold Features | Feature | Description | | -------------------------- | --------------------------------------------------------- | | **Automatic Preservation** | Entities matching hold scope are automatically preserved | | **Retention Override** | Legal holds override data retention policies | | **Custodian Notification** | Custodians are notified of their preservation obligations | | **Compliance Tracking** | Track custodian acknowledgment and compliance | | **Chain of Custody** | Maintain evidence chain of custody documentation | | **Audit Trail** | All hold actions are logged in the audit trail | ## E-Discovery Support CaseBender supports the full e-discovery lifecycle: ### E-Discovery Workflow 1. **Request**: Receive and track e-discovery requests with deadlines and scope 2. **Collection**: Collect responsive data from cases, alerts, comments, and audit logs 3. **Review**: Review collected data in dedicated review sets with tagging and annotation 4. **Production**: Produce responsive documents in required formats 5. **Export**: Generate export packages for legal counsel ### Review Capabilities * **Review Sets**: Organize collected data into review sets for efficient review * **Tagging**: Tag documents as responsive, privileged, or irrelevant * **Bulk Review**: Review multiple items simultaneously with consistent tagging * **Decision Tracking**: Track review decisions with reviewer attribution * **Export Formats**: PDF, CSV, native format, and structured data packages ## Data Retention for Audit Logs Audit logs follow configurable retention policies: | Data Type | Default Retention | Compliance Requirement | | --------------------- | ----------------- | ---------------------- | | Authentication events | 3 years | SOC2, ISO 27001, CMMC | | Authorization events | 3 years | SOC2, ISO 27001, HIPAA | | Data access events | 3 years | GDPR, HIPAA, PCI DSS | | Configuration changes | 7 years | SEC Rule 17a-4 | | Security events | 3 years | SOC2, CMMC, FedRAMP | | Compliance evidence | 7 years | Multiple frameworks | Audit logs under legal hold are retained indefinitely regardless of retention policy settings. ## Related Documentation * [Security Architecture](/en/security/architecture) — How audit logging fits into the security design * [Compliance Overview](/en/security/compliance-overview) — How audit logs provide compliance evidence * [Threat Detection](/en/security/behavioral-analytics) — UEBA and SIEM integration # Authentication Source: https://docs.casebender.com/en/security/authentication Multi-factor authentication, SSO, account lockout, and step-up authentication in CaseBender. ## Multi-Factor Authentication CaseBender supports multiple MFA methods to protect user accounts. MFA can be enforced at the organization level, ensuring all users comply with your security policy. ### TOTP (Time-Based One-Time Password) Standard TOTP authentication compatible with all major authenticator apps: * **Google Authenticator** * **Microsoft Authenticator** * **Authy** * **1Password** * Any TOTP-compatible app (RFC 6238) Setup process: 1. User navigates to Security Settings 2. Scans QR code with their authenticator app 3. Enters a verification code to confirm enrollment 4. Backup codes are generated for account recovery ### WebAuthn / FIDO2 Hardware Tokens For organizations requiring phishing-resistant authentication: * **YubiKey** (USB-A, USB-C, NFC) * **Google Titan** Security Keys * **Windows Hello** (biometric) * **Apple Touch ID / Face ID** (platform authenticators) * Any FIDO2-compliant authenticator WebAuthn provides the strongest authentication because: * Credentials are bound to the origin (phishing-resistant) * Private keys never leave the hardware token * No shared secrets that can be intercepted * Supports user verification (PIN or biometric) ### Backup Codes When enrolling in MFA, users receive one-time backup codes for account recovery: * 10 single-use codes generated at enrollment * Each code can only be used once * Codes are hashed before storage (cannot be retrieved, only verified) * New codes can be regenerated (invalidates all previous codes) ## Single Sign-On (SSO) ### SAML 2.0 CaseBender supports SAML 2.0 for enterprise SSO integration: * **Identity Providers**: Okta, Azure AD, OneLogin, PingFederate, ADFS, and any SAML 2.0 compliant IdP * **SP-Initiated SSO**: Users start at CaseBender and are redirected to the IdP * **IdP-Initiated SSO**: Users start at the IdP portal and are directed to CaseBender * **Single Logout (SLO)**: Logging out of CaseBender terminates the IdP session * **Attribute Mapping**: Map IdP attributes to CaseBender user fields (name, email, role, team) ### SCIM Provisioning Automate user lifecycle management with SCIM 2.0: * **User Provisioning**: Automatically create CaseBender accounts when users are added in your IdP * **User Deprovisioning**: Automatically disable accounts when users are removed from the IdP * **Group Sync**: Map IdP groups to CaseBender teams and roles * **Profile Updates**: Changes in the IdP (name, email, department) sync to CaseBender automatically ### Just-In-Time (JIT) Provisioning For organizations that prefer not to use SCIM: * Users are automatically created on first SSO login * Default role and team assignments are configurable * Attribute mapping determines initial permissions * Administrators can review and adjust JIT-provisioned accounts ## Account Lockout CaseBender implements progressive account lockout to prevent brute-force attacks: ### Lockout Policy | Attempt | Action | | ------- | ---------------------------------------- | | 1-4 | Normal login flow | | 5 | Account locked for 5 minutes | | 6-9 | Extended lockout with progressive delays | | 10+ | Account locked until admin intervention | ### Lockout Features * **Progressive Delays**: Each subsequent lockout increases the wait time * **IP-Based Tracking**: Failed attempts are tracked per IP address in addition to per account * **Admin Unlock**: Administrators can manually unlock accounts * **Notification**: Users and administrators are notified of lockout events * **Audit Trail**: All lockout events are logged with IP address, user agent, and timestamp ## Step-Up Authentication Even with a valid session, CaseBender requires re-authentication for sensitive operations: ### Operations Requiring Step-Up * Changing security settings (MFA, SSO configuration) * Modifying RBAC policies or role assignments * Bulk delete operations (cases, alerts, tasks) * Exporting audit logs or sensitive data * Privileged access elevation (PAM) * Changing integration credentials * Modifying data retention policies ### Step-Up Methods Users can satisfy step-up requirements using any enrolled MFA method: * TOTP code from authenticator app * WebAuthn/FIDO2 hardware token tap * Backup code (one-time use) Step-up sessions have a configurable expiry (default: 15 minutes) after which re-authentication is required again. ## Session Management * **Configurable Session Duration**: Organizations can set session timeout policies * **Concurrent Session Limits**: Configurable maximum concurrent sessions per user * **Session Revocation**: Administrators can terminate any user's active sessions * **Idle Timeout**: Sessions expire after configurable inactivity period * **Secure Cookies**: HTTP-only, Secure, SameSite=Strict cookie attributes ## Related Documentation * [Access Control](/en/security/access-control) — RBAC, PAM, and API security * [Security Architecture](/en/security/architecture) — Zero Trust design principles * [Audit Logging](/en/security/audit-logging) — Authentication event logging # Threat Detection Source: https://docs.casebender.com/en/security/behavioral-analytics User and Entity Behavior Analytics (UEBA), insider threat detection, DDoS protection, and SIEM integration. ## User and Entity Behavior Analytics (UEBA) CaseBender includes a built-in UEBA engine that establishes behavioral baselines for every user and detects anomalies that may indicate compromised accounts or malicious activity. ### Behavioral Categories Monitored | Category | What's Tracked | Example Anomaly | | ------------------- | ----------------------------------------------- | ------------------------------------------ | | **Authentication** | Login times, locations, devices, MFA usage | Login from new country at unusual hour | | **Data Access** | Cases viewed, searches performed, exports | Bulk case access outside normal pattern | | **Case Operations** | Cases created, modified, closed, reassigned | Unusual volume of case closures | | **Administrative** | Settings changes, user management, role changes | Privilege escalation outside change window | | **API Usage** | Endpoint access patterns, data volumes | Sudden spike in API calls from a key | | **Communication** | Comments, notifications, sharing patterns | Mass sharing of restricted cases | ### How Baselines Work 1. **Learning Period**: The system observes user behavior for a configurable baseline window (default: 30 days) 2. **Feature Extraction**: Behavioral features are extracted (time patterns, volume patterns, entity patterns) 3. **Baseline Establishment**: Statistical baselines are created per user and per peer group 4. **Continuous Comparison**: Every action is compared against the user's baseline and their peer group 5. **Anomaly Scoring**: Deviations are scored based on magnitude, frequency, and risk context ### Peer Group Analysis Users are automatically grouped by role, team, and behavior patterns. Anomalies are evaluated both against individual baselines and peer group norms: * A SOC analyst accessing 50 cases per day is normal if their peers do the same * The same access pattern from a user who normally accesses 5 cases per day is anomalous * Peer group deviations are weighted differently from individual deviations ### Risk Scoring Each user maintains a dynamic risk score: | Risk Level | Score Range | Response | | ------------ | ----------- | ------------------------------------------------------------------------------ | | **Critical** | 90-100 | Immediate alert to security team, session review, potential account suspension | | **High** | 70-89 | Alert generated, enhanced monitoring enabled, manager notified | | **Medium** | 40-69 | Logged for review, included in daily security digest | | **Low** | 10-39 | Normal monitoring, baseline adjustment | | **Minimal** | 0-9 | Standard operations | ### ML Adapter CaseBender's UEBA engine includes an ML adapter interface for organizations that want to integrate advanced machine learning models: * Feature vector extraction for external ML pipelines * Anomaly prediction integration * Model health monitoring * Supports custom model deployment alongside built-in statistical detection ## Insider Threat Detection CaseBender provides dedicated insider threat detection capabilities that go beyond UEBA to include investigation workflows, watchlists, and escalation management. ### Threat Indicators The system monitors for indicators across multiple categories: * **Data Exfiltration**: Unusual export volumes, bulk downloads, access to cases outside assignment * **Privilege Abuse**: Unauthorized configuration changes, role manipulation, PAM misuse * **Policy Violations**: Access outside business hours, from unauthorized locations, bypassing controls * **Behavioral Changes**: Sudden changes in work patterns, increased access to sensitive data * **Pre-Departure Risk**: Access pattern changes correlated with HR signals (resignation, termination) ### Investigation Workflow When indicators are detected: 1. **Alert Generation**: Insider threat alert created with risk score and indicator details 2. **Triage**: Security team reviews the alert and determines if investigation is warranted 3. **Investigation**: Dedicated investigation workspace with timeline, evidence collection, and notes 4. **Watchlist**: Users can be placed on enhanced monitoring watchlists with configurable monitoring levels 5. **Escalation**: Configurable escalation rules route investigations to appropriate teams (security, HR, legal) 6. **Resolution**: Investigations are closed with documented findings and actions taken ### Integration Points * **HR Systems**: Receive employment status changes (resignation, termination, role change) to adjust risk scoring * **SIEM**: Forward insider threat events to your SIEM for correlation with other security data * **Legal Hold**: Automatically initiate legal holds when investigations reach certain severity thresholds * **Notification**: Alert security managers, HR, and legal teams based on escalation rules ## DDoS Protection CaseBender includes application-layer DDoS detection and mitigation: ### Detection Methods * **Traffic Analysis**: Real-time monitoring of request rates, patterns, and sources * **Request Fingerprinting**: Identifies coordinated attacks from distributed sources * **Geo-Blocking**: Configurable country-level blocking for regions with no legitimate users * **Anomaly Detection**: Statistical analysis of traffic patterns against established baselines ### Mitigation * **Automatic Rate Limiting**: Progressive rate limiting as attack severity increases * **Challenge Pages**: CAPTCHA challenges for suspicious traffic patterns * **IP Blocking**: Temporary or permanent blocking of identified attack sources * **Alerting**: Real-time alerts to operations team with attack details and mitigation status CaseBender's DDoS protection operates at the application layer. For volumetric network-layer DDoS protection, deploy CaseBender behind a dedicated DDoS mitigation service (e.g., Cloudflare, AWS Shield, or on-premise appliances). ## SIEM Integration CaseBender forwards security events to your existing SIEM for centralized monitoring and correlation. ### Supported Destinations | SIEM | Protocol | Format | | ---------------------- | -------------------------- | --------------- | | **Splunk** | HTTP Event Collector (HEC) | JSON, CEF | | **Elastic / ELK** | Elasticsearch API | JSON (ECS) | | **IBM QRadar** | Syslog | LEEF | | **Microsoft Sentinel** | Log Analytics API | JSON | | **Generic Syslog** | Syslog (TCP/UDP/TLS) | CEF, LEEF, JSON | | **Custom Webhook** | HTTPS POST | JSON | ### Events Forwarded * Authentication events (login, logout, MFA, lockout) * Authorization events (access granted, denied, elevated) * Data access events (entity viewed, exported, modified) * Security events (anomaly detected, threat indicator, policy violation) * Administrative events (configuration change, user management) * System events (service health, error conditions) ### Configuration SIEM forwarding is configured per organization: * Multiple destinations can be configured simultaneously * Event filtering controls which event types are forwarded * Buffering and retry logic ensures no events are lost during SIEM outages * TLS encryption for all forwarded events ## Related Documentation * [Access Control](/en/security/access-control) — RBAC and PAM that generate the events UEBA monitors * [Audit Logging](/en/security/audit-logging) — The audit trail that feeds UEBA and SIEM * [Security Architecture](/en/security/architecture) — Zero Trust design that UEBA enforces # Code Security Source: https://docs.casebender.com/en/security/code-security Static analysis, dynamic testing, vulnerability management, penetration testing, and license compliance in CaseBender. ## Overview CaseBender's code security program covers the entire software development lifecycle — from static analysis during development to dynamic testing in staging, continuous vulnerability monitoring in production, and regular penetration testing by third parties. ### Live Security Scan Status ![Security Scan](https://github.com/casebender/webapp/actions/workflows/security-scan.yml/badge.svg?branch=main) This badge represents 12 automated security checks that run on every code change. ## Static Application Security Testing (SAST) ### ESLint Security Rules Every pull request is scanned with ESLint security rules that detect: * Use of `eval()` and `Function()` constructor * `dangerouslySetInnerHTML` in React components * Hardcoded secrets and credentials * Insecure regular expressions (ReDoS) * Prototype pollution patterns ### Semgrep Deep Analysis [Semgrep](https://semgrep.dev/) provides deep taint analysis across the TypeScript and Next.js codebase: * **OWASP Top 10 Rules**: Injection, broken authentication, sensitive data exposure, XSS, insecure deserialization * **TypeScript-Specific Rules**: Type confusion, unsafe type assertions, prototype pollution * **Next.js-Specific Rules**: Server-side request forgery, open redirects, insecure API routes * **Custom Rules**: CaseBender-specific patterns for common security mistakes ### Secret Detection [Gitleaks](https://gitleaks.io/) scans every commit for accidentally committed secrets: * API keys and tokens * Database connection strings * Private keys and certificates * Cloud provider credentials * Generic high-entropy strings Gitleaks scans both the current commit and the full git history to catch secrets that may have been committed and later removed. ## Dynamic Application Security Testing (DAST) ### OWASP ZAP [OWASP ZAP](https://www.zaproxy.org/) performs full active scanning against the running application: * **Schedule**: Weekly (every Sunday at 2 AM UTC) * **Scan Type**: Full active scan (not just passive observation) * **Target**: Complete application surface including API endpoints * **Results**: SARIF format uploaded to GitHub Code Scanning ### What ZAP Tests * SQL injection * Cross-site scripting (XSS) * Cross-site request forgery (CSRF) * Server-side request forgery (SSRF) * Directory traversal * Remote code execution * Authentication bypass * Session management flaws * Information disclosure ## Vulnerability Management ### Continuous Scanning Vulnerabilities are detected through multiple channels: | Scanner | Target | Schedule | Severity Gate | | ---------------------------- | --------------------------------- | ---------- | -------------------------- | | **Trivy (Filesystem)** | npm dependencies | Every PR | CRITICAL, HIGH | | **Trivy (Container)** | Container images (all 7 services) | Every PR | CRITICAL, HIGH | | **Trivy (IaC)** | Dockerfiles, Kubernetes configs | Every PR | CRITICAL, HIGH | | **pnpm audit** | Production dependencies | Every PR | CRITICAL, HIGH | | **Dependabot** | All dependencies | Continuous | Automatic PRs | | **GitHub Dependency Review** | New/changed dependencies | Every PR | CRITICAL, HIGH block merge | ### Vulnerability SLAs When vulnerabilities are discovered, they must be remediated within defined SLAs: | Severity | Remediation SLA | Escalation | | ---------------------------- | --------------- | --------------------------- | | **Critical** (CVSS 9.0-10.0) | 24 hours | Immediate team notification | | **High** (CVSS 7.0-8.9) | 7 days | Daily standup review | | **Medium** (CVSS 4.0-6.9) | 30 days | Weekly review | | **Low** (CVSS 0.1-3.9) | 90 days | Quarterly review | ### Risk Acceptance When a vulnerability cannot be immediately remediated (e.g., no patch available), CaseBender follows a formal risk acceptance process: 1. **Documentation**: Vulnerability details, affected components, and business impact 2. **Justification**: Why remediation is not immediately possible 3. **Mitigation**: Compensating controls in place to reduce risk 4. **Review Date**: Mandatory review date (maximum 90 days) 5. **Approval**: Security team approval required Risk acceptances are tracked in `.trivyignore` with full documentation and quarterly review. ## Penetration Testing CaseBender includes a penetration testing management module: ### Engagement Management * **Engagement Tracking**: Schedule and track penetration testing engagements * **Scope Definition**: Define testing scope, rules of engagement, and authorized techniques * **Finding Management**: Track findings with severity, status, and remediation progress * **Remediation SLAs**: Findings must be remediated within severity-based SLAs ### Remediation SLAs | Finding Severity | Remediation Deadline | | ----------------- | -------------------- | | **Critical** | 15 days | | **High** | 30 days | | **Medium** | 60 days | | **Low** | 90 days | | **Informational** | Next release cycle | ## License Compliance ### Automated License Scanning Every dependency's license is checked automatically: * **Blocked Licenses**: Copyleft licenses (GPL, AGPL, LGPL) are blocked from entering the codebase * **Allowed Licenses**: MIT, Apache 2.0, BSD, ISC, and other permissive licenses * **Review Required**: Uncommon or unknown licenses are flagged for legal review * **No License**: Dependencies without a declared license are blocked ### License Scanning Pipeline Trivy performs license scanning as part of the security scan workflow: ``` Dependency Added → License Detected → Policy Check → Allowed / Blocked / Review Required ``` ## Input Validation CaseBender implements comprehensive input validation to prevent injection attacks: ### HTML Sanitization * All user-provided HTML (comments, descriptions) is sanitized before storage and rendering * Allowlisted tags and attributes only * Script tags, event handlers, and data URIs are stripped ### File Upload Validation * MIME type verification (not just extension checking) * Blocked extensions: `.exe`, `.bat`, `.cmd`, `.ps1`, `.sh`, `.dll`, `.so` * Maximum file size enforcement (configurable per upload type) * Evidence uploads have separate, stricter validation ### URL Validation (SSRF Prevention) * External URLs are validated before any server-side requests * Private IP ranges (10.x, 172.16-31.x, 192.168.x, 127.x) are blocked * Internal hostnames and cloud metadata endpoints are blocked * DNS rebinding protection via pre-resolution validation ### Request Sanitization * Null byte stripping from all string inputs * Unicode normalization to prevent homograph attacks * Zod schema validation on every API endpoint * Parameterized queries via Prisma ORM (no raw SQL) ## Security Gate All security checks must pass before code can be merged to the main branch: ``` PR Created ├── Gitleaks (secret detection) ├── Trivy (dependency scan) ├── Trivy (container scan × 7 services) ├── Trivy (IaC scan) ├── ESLint Security ├── Semgrep SAST ├── pnpm audit ├── License compliance ├── Dependency review └── Supply chain verification │ ▼ Security Gate (all must pass) │ ▼ Merge Allowed ``` The security gate is enforced via GitHub branch protection rules. It cannot be bypassed, even by repository administrators. ## Related Documentation * [Supply Chain Security](/en/security/supply-chain) — Container signing, SBOM, and provenance * [Security Overview](/en/security/overview) — Live pipeline status * [Hardening Guide](/en/security/hardening-guide) — Deployment security recommendations # Additional Compliance Frameworks Source: https://docs.casebender.com/en/security/compliance-additional CaseBender's support for CMMC, FedRAMP, HIPAA, PCI DSS, Export Control, and EU AI Act compliance. ## CMMC Level 2 CaseBender supports Cybersecurity Maturity Model Certification (CMMC) Level 2, which requires implementation of 110 practices from NIST SP 800-171. ### Key Capabilities * **Practice Management**: Track all 110 CMMC Level 2 practices across 14 domains * **SPRS Scoring**: Calculate and track your Supplier Performance Risk System (SPRS) score over time * **Assessment Tracking**: Manage self-assessments and third-party assessments (C3PAO) * **POA\&M Management**: Track Plans of Action and Milestones for practices not yet fully implemented * **Evidence Collection**: Automated collectors gather evidence mapped to specific practices ### Domain Coverage | Domain | Practices | Description | | ----------------------------------------- | --------- | ------------------------------------------------------- | | **AC** Access Control | 22 | Account management, access enforcement, remote access | | **AT** Awareness & Training | 3 | Security awareness, role-based training | | **AU** Audit & Accountability | 9 | Audit logging, audit review, audit protection | | **CM** Configuration Management | 9 | Baseline configuration, change control | | **IA** Identification & Authentication | 11 | MFA, device authentication, credential management | | **IR** Incident Response | 3 | Incident handling, reporting, testing | | **MA** Maintenance | 6 | System maintenance, maintenance tools | | **MP** Media Protection | 4 | Media access, storage, transport | | **PE** Physical Protection | 6 | Physical access, monitoring, visitor control | | **PS** Personnel Security | 2 | Personnel screening, termination | | **RA** Risk Assessment | 3 | Risk assessment, vulnerability scanning | | **CA** Security Assessment | 4 | Assessment, monitoring, system connections | | **SC** System & Communications Protection | 16 | Boundary protection, encryption, key management | | **SI** System & Information Integrity | 7 | Flaw remediation, malicious code protection, monitoring | *** ## FedRAMP Moderate CaseBender supports FedRAMP Moderate authorization, implementing controls from NIST SP 800-53 Rev 5. ### Key Capabilities * **Control Management**: Track all 325 FedRAMP Moderate controls with implementation status * **System Security Plan (SSP)**: Manage SSP documentation with version control and approval workflows * **Continuous Monitoring (ConMon)**: Automated monthly reporting on control effectiveness * **POA\&M Management**: Track remediation plans with OMB A-130 compliance * **Authorization Periods**: Manage authorization boundaries, ATOs, and reauthorization schedules * **Significant Change Management**: Track and assess significant changes that may affect authorization ### Control Families CaseBender maps its capabilities to all 20 NIST SP 800-53 control families, with particular strength in: * **AC** (Access Control): RBAC, MFA, session management, PAM * **AU** (Audit and Accountability): Unified audit trail, integrity protection, SIEM forwarding * **IA** (Identification and Authentication): Multi-factor, device trust, service authentication * **IR** (Incident Response): Case management, playbooks, SLA tracking * **SC** (System and Communications Protection): Encryption, TLS, network segmentation *** ## HIPAA CaseBender supports HIPAA compliance for organizations that handle Protected Health Information (PHI) as part of security operations. ### Security Rule Safeguards #### Administrative Safeguards (164.308) | Safeguard | CaseBender Implementation | | -------------------------------- | ---------------------------------------------------------------- | | Security Management Process | Risk assessment, vulnerability management, security monitoring | | Assigned Security Responsibility | RBAC with defined security roles | | Workforce Security | SCIM provisioning, access termination, insider threat monitoring | | Information Access Management | TLP-based access control, data classification, PAM | | Security Awareness & Training | Compliance training module with HIPAA-specific programs | | Security Incident Procedures | Case management, incident response workflows, SLA tracking | | Contingency Plan | Data retention, backup management, disaster recovery | | Evaluation | Compliance dashboards, control testing, gap analysis | #### Technical Safeguards (164.312) | Safeguard | CaseBender Implementation | | --------------------- | --------------------------------------------------------------------- | | Access Control | Unique user identification, emergency access, auto-logoff, encryption | | Audit Controls | Unified audit trail with PHI access logging | | Integrity | Data integrity verification, tamper-evident audit logs | | Authentication | MFA, WebAuthn, SSO, account lockout | | Transmission Security | TLS 1.3, encrypted inter-service communication | ### Breach Notification Rule (164.404-408) * **Individual Notification**: Generate and track notifications to affected individuals * **HHS Notification**: Manage notification to the Department of Health and Human Services * **Media Notification**: For breaches affecting 500+ individuals, manage media notifications * **Breach Documentation**: Maintain breach records for 6 years as required ### Business Associate Agreements * Track BAAs with all business associates * Monitor BAA expiration dates and renewal requirements * Document BAA terms and data handling obligations *** ## PCI DSS v4.0 CaseBender supports PCI DSS v4.0 for organizations that process payment card data in security investigations. ### Key Capabilities * **Requirement Tracking**: All 12 PCI DSS requirements with 78 sub-requirements * **Evidence Collection**: Automated collectors for access controls, encryption, logging, and network security * **Control Testing**: Scheduled testing with evidence capture and result tracking * **Incident Management**: PCI-specific incident tracking with notification requirements * **Assessment Periods**: Manage QSA assessments and self-assessment questionnaires ### Requirement Coverage | Requirement | Description | CaseBender Mapping | | ----------- | ----------------------------- | -------------------------------------------------- | | **1** | Network Security Controls | Network segmentation, firewall configuration | | **2** | Secure Configurations | Container hardening, configuration management | | **3** | Protect Stored Data | Encryption at rest, key management, data retention | | **4** | Protect Data in Transit | TLS 1.3, encrypted communications | | **5** | Malicious Software Protection | Container scanning, dependency scanning | | **6** | Secure Development | SAST, DAST, code review, vulnerability management | | **7** | Restrict Access | RBAC, least privilege, PAM | | **8** | Identify Users | MFA, unique IDs, authentication management | | **9** | Physical Access | On-premise deployment documentation | | **10** | Log and Monitor | Unified audit trail, SIEM forwarding, integrity | | **11** | Test Security | Penetration testing, vulnerability scanning | | **12** | Organizational Policies | Policy management, training, incident response | *** ## Export Control CaseBender includes export control compliance for organizations handling controlled technology data. ### Key Capabilities * **ECCN/ITAR Classification**: Classify security data and tools under Export Administration Regulations (EAR) and International Traffic in Arms Regulations (ITAR) * **Denied Party Screening**: Screen entities against government restricted and denied party lists before data sharing * **Country Controls**: Enforce embargoed and restricted country rules on data access and sharing * **License Management**: Track export licenses with expiration dates and usage limits * **Auto-Classification Engine**: Suggest classifications based on data content and context ### Screening Lists CaseBender screens against: * Consolidated Screening List (CSL) * Entity List (BIS) * Specially Designated Nationals (OFAC SDN) * Denied Persons List (BIS) * Debarred List (DDTC) *** ## EU AI Act CaseBender supports EU AI Act compliance for organizations using AI capabilities within the platform. ### Key Capabilities * **AI System Registration**: Register and catalog AI systems used within CaseBender (AI insights, auto-enrichment, correlation engine) * **Risk Assessment**: Evaluate AI systems against EU AI Act risk categories (minimal, limited, high, unacceptable) * **Incident Reporting**: Report and track AI-related incidents with root cause analysis * **Conformity Assessment**: Manage conformity assessments for high-risk AI systems * **Human Oversight**: Document human oversight mechanisms for AI-assisted decisions * **Transparency**: Maintain transparency records showing how AI systems make recommendations *** ## Related Documentation * [Compliance Overview](/en/security/compliance-overview) — Framework matrix and unified compliance * [SOC2 Type II](/en/security/compliance-soc2) — SOC2 deep dive * [ISO 27001:2022](/en/security/compliance-iso27001) — ISO 27001 deep dive * [GDPR & Privacy](/en/security/compliance-gdpr) — GDPR deep dive # GDPR & Privacy Source: https://docs.casebender.com/en/security/compliance-gdpr CaseBender's GDPR compliance features including data subject rights, consent management, breach notification, and cross-border transfer controls. ## Overview CaseBender provides comprehensive GDPR compliance capabilities for organizations that process personal data as part of security operations. As an on-premise platform, CaseBender gives you full control over data processing — your data never leaves your infrastructure. ## Data Subject Rights ### Right of Access (Article 15) CaseBender supports Data Subject Access Requests (DSARs): * **Request Management**: Track DSARs from receipt through fulfillment with SLA monitoring * **Data Discovery**: Automatically discover all data associated with a data subject across cases, alerts, comments, audit logs, and observables * **Data Export**: Generate structured data packages for data subject delivery * **Deadline Tracking**: 30-day response deadline with extension management * **Acknowledgment**: Automated acknowledgment to data subjects upon request receipt ### Right to Erasure (Article 17) CaseBender implements the right to be forgotten with safeguards: * **Erasure Execution Engine**: Systematically erases personal data across all platform entities * **PII Registry**: Comprehensive mapping of where personal data is stored in every database model * **Anonymization**: Where full deletion would compromise audit integrity, data is anonymized using consistent markers * **Legal Hold Check**: Erasure requests are automatically checked against active legal holds * **Verification Report**: Post-erasure verification confirms all personal data has been removed or anonymized * **Audit Trail**: The erasure action itself is logged (without the erased data) for compliance evidence ### Right to Rectification (Article 16) * Users can update their personal information through their profile * Administrators can correct data on behalf of data subjects * All changes are tracked in the audit trail ### Right to Data Portability (Article 20) * Data export in structured, machine-readable formats (JSON, CSV) * Includes all data the subject provided to the platform * Export packages are encrypted for secure delivery ## Consent Management ### Consent Lifecycle CaseBender tracks consent throughout its lifecycle: 1. **Collection**: Record consent with purpose, legal basis, and timestamp 2. **Storage**: Consent records are stored with cryptographic integrity 3. **Verification**: Check consent status before processing operations 4. **Withdrawal**: Data subjects can withdraw consent at any time 5. **Impact Assessment**: Withdrawal triggers an impact analysis showing what processing will stop ### Processing Activities Register (Article 30) Maintain a register of processing activities: * **Activity Catalog**: Document each processing activity with purpose, legal basis, and data categories * **Data Flow Mapping**: Track where personal data flows within the platform * **Retention Periods**: Document retention periods per processing activity * **Third-Party Sharing**: Record any data sharing with third parties (integrations) ## Breach Notification ### Article 33 — Notification to Supervisory Authority CaseBender supports the 72-hour breach notification requirement: * **Breach Detection**: Security monitoring and UEBA detect potential breaches * **Breach Recording**: Document breach details, affected data, and impact assessment * **Authority Notification**: Generate notification documents for supervisory authorities * **Timeline Tracking**: Track the 72-hour deadline with escalation alerts * **Follow-Up**: Manage supplementary notifications as more information becomes available ### Article 34 — Notification to Data Subjects When a breach is likely to result in high risk to individuals: * **Subject Identification**: Identify affected data subjects from breach scope * **Notification Generation**: Generate clear, plain-language notifications * **Delivery Tracking**: Track notification delivery and acknowledgment * **Remediation Guidance**: Include recommended protective measures for affected individuals ## Privacy Impact Assessment ### Automated PIA (Article 35) CaseBender automates Data Protection Impact Assessments: * **Personal Data Detection**: Automatically scan entities for personal data patterns * **Risk Assessment**: Evaluate processing risks based on data types, volume, and sensitivity * **Mitigation Recommendations**: Suggest privacy-enhancing measures based on identified risks * **Review Workflow**: PIAs are reviewed and approved by the Data Protection Officer * **Continuous Monitoring**: PIAs are re-evaluated when processing activities change ## Cross-Border Transfer Controls ### Transfer Safeguards (Articles 44-49) CaseBender enforces data residency and cross-border transfer rules: * **Data Residency Policies**: Define where data can be stored and processed by jurisdiction * **Transfer Rules**: Configure rules for when data can cross borders (adequacy decisions, SCCs, BCRs) * **Transfer Evaluation**: Automatically evaluate proposed transfers against configured rules * **Violation Detection**: Detect and alert on unauthorized cross-border data flows * **Transfer Heatmap**: Visualize data flows across jurisdictions ### Supported Transfer Mechanisms | Mechanism | Description | | -------------------------------- | ------------------------------------------------ | | **Adequacy Decision** | Transfer to countries with EU adequacy decisions | | **Standard Contractual Clauses** | Transfer under approved SCCs | | **Binding Corporate Rules** | Intra-group transfers under BCRs | | **Explicit Consent** | Transfer with explicit data subject consent | | **Legal Obligation** | Transfer required by law | ## Privacy-Aware Logging CaseBender implements privacy by design in its logging: * **PII Redaction**: Personal data is automatically redacted from application logs * **Configurable Redaction Paths**: Define which fields are redacted in log output * **Audit vs. Application Logs**: Audit logs retain necessary detail for compliance; application logs are privacy-safe * **Redaction Strategies**: Support for masking, hashing, and full removal ## Related Documentation * [Data Protection](/en/security/data-protection) — Encryption and data retention * [Compliance Overview](/en/security/compliance-overview) — All supported frameworks * [Audit Logging](/en/security/audit-logging) — Audit trail and integrity # ISO 27001:2022 Source: https://docs.casebender.com/en/security/compliance-iso27001 CaseBender's ISO 27001:2022 compliance support including ISMS controls, risk management, internal audit, and Statement of Applicability. ## Overview CaseBender provides comprehensive ISO 27001:2022 Information Security Management System (ISMS) support. The platform maps its security controls to the ISO 27001 Annex A control set and provides tools for risk management, internal audit, and continuous improvement. ## Annex A Control Coverage ### Organizational Controls (A.5) | Control | Description | CaseBender Implementation | | ---------- | ------------------------------------------ | ------------------------------------------------------------ | | **A.5.1** | Policies for information security | Policy management, version control, acknowledgment tracking | | **A.5.2** | Information security roles | RBAC with defined security responsibilities per role | | **A.5.3** | Segregation of duties | Role separation, PAM for privileged operations | | **A.5.7** | Threat intelligence | MITRE ATT\&CK integration, MISP threat feeds, IOC enrichment | | **A.5.23** | Information security for cloud services | On-premise deployment, cloud hardening guides | | **A.5.24** | Incident management planning | Case templates, playbook automation, SLA management | | **A.5.25** | Assessment of information security events | Alert triage workflows, severity scoring, correlation engine | | **A.5.26** | Response to information security incidents | Case management workflows, task assignment, escalation | | **A.5.28** | Collection of evidence | Evidence management, chain of custody, legal hold | ### People Controls (A.6) | Control | Description | CaseBender Implementation | | --------- | ---------------------------------- | ----------------------------------------------------------------- | | **A.6.1** | Screening | Integration with HR systems for background check tracking | | **A.6.3** | Information security awareness | Compliance training module, campaign management | | **A.6.5** | Responsibilities after termination | SCIM deprovisioning, access revocation, insider threat monitoring | ### Technological Controls (A.8) | Control | Description | CaseBender Implementation | | ---------- | ------------------------------ | -------------------------------------------------------------- | | **A.8.1** | User endpoint devices | Device trust assessment, security posture evaluation | | **A.8.2** | Privileged access rights | PAM with just-in-time elevation, session recording | | **A.8.3** | Information access restriction | TLP-based access control, data classification enforcement | | **A.8.5** | Secure authentication | MFA (TOTP + WebAuthn), SSO (SAML 2.0), account lockout | | **A.8.9** | Configuration management | Immutable container images, infrastructure as code | | **A.8.10** | Information deletion | Data retention policies, secure erasure, legal hold exemptions | | **A.8.11** | Data masking | PII redaction in logs, privacy-aware logging | | **A.8.12** | Data leakage prevention | Data classification, export controls, UEBA monitoring | | **A.8.15** | Logging | Unified audit trail, tamper-evident integrity, SIEM forwarding | | **A.8.16** | Monitoring activities | UEBA, security monitoring, anomaly detection | | **A.8.24** | Use of cryptography | AES-256 encryption, TLS 1.3, key rotation, secrets management | ## Risk Management CaseBender includes a dedicated ISO 27001 risk management module: ### Risk Register * **Risk Identification**: Catalog information security risks with threat and vulnerability mapping * **Risk Assessment**: Likelihood and impact scoring using configurable risk matrices * **Risk Treatment**: Define treatment plans with milestones, owners, and deadlines * **Risk Acceptance**: Formal risk acceptance workflow with management approval and documentation * **Risk Monitoring**: Track risk levels over time with trend analysis ### Risk Matrix Risks are evaluated on a 5x5 matrix: | | Negligible | Minor | Moderate | Major | Catastrophic | | ------------------ | ---------- | ------ | -------- | -------- | ------------ | | **Almost Certain** | Medium | High | High | Critical | Critical | | **Likely** | Low | Medium | High | High | Critical | | **Possible** | Low | Medium | Medium | High | High | | **Unlikely** | Low | Low | Medium | Medium | High | | **Rare** | Low | Low | Low | Medium | Medium | ### Treatment Plans Each risk treatment plan includes: * Treatment strategy (mitigate, transfer, accept, avoid) * Specific actions with owners and deadlines * Milestones for tracking progress * Residual risk assessment after treatment * Review schedule for ongoing monitoring ## Statement of Applicability (SoA) The SoA documents which Annex A controls are applicable to your deployment: * **Applicable Controls**: Controls that are relevant and implemented * **Not Applicable Controls**: Controls excluded with documented justification * **Implementation Status**: Current implementation level per control * **Evidence Links**: Direct links to evidence artifacts for each control * **Approval Workflow**: SoA changes require management approval ## Internal Audit ### Audit Cycle Management * **Audit Planning**: Define audit scope, schedule, and team assignments * **Audit Execution**: Guided audit procedures with evidence collection * **Finding Management**: Track findings by severity (major nonconformity, minor nonconformity, observation, opportunity for improvement) * **Corrective Actions**: Assign and track corrective actions with deadlines * **Verification**: Verify corrective action effectiveness before closure * **Management Review**: Aggregate audit results for management review meetings ### Evidence Collection Automated collectors gather ISO 27001-specific evidence: * Access control configurations and reviews * Security event logs and incident records * Change management records * Training and awareness records * Risk assessment documentation * Business continuity test results ## Reporting * **Compliance Dashboard**: Real-time view of ISO 27001 control implementation status * **Gap Analysis Report**: Identify unimplemented or partially implemented controls * **Risk Report**: Current risk landscape with treatment status * **Audit Report**: Internal audit findings and corrective action status * **Management Review Package**: Aggregated data for management review meetings ## Related Documentation * [Compliance Overview](/en/security/compliance-overview) — All supported frameworks * [Data Protection](/en/security/data-protection) — Encryption and data handling controls * [Threat Detection](/en/security/behavioral-analytics) — Monitoring and detection capabilities # Compliance Overview Source: https://docs.casebender.com/en/security/compliance-overview CaseBender supports 10+ compliance frameworks with built-in evidence collection, control testing, and audit management. ## Compliance Framework Support CaseBender includes native support for major compliance frameworks. Each framework implementation includes control mapping, automated evidence collection, gap analysis, and reporting — built directly into the platform, not bolted on. ### Framework Matrix | Framework | Standard | Implementation | Evidence Collection | Reporting | | -------------------- | ------------------ | ----------------------------------------------------------------------- | ----------------------------------------- | -------------------------------------------- | | **SOC2 Type II** | AICPA TSC 2017 | Trust Service Criteria mapping, control testing, attestation management | Automated collectors, 3-year retention | Audit period reports, gap analysis | | **ISO 27001:2022** | ISO/IEC 27001:2022 | Full Annex A controls, Statement of Applicability, risk register | Automated collectors, evidence review | Internal audit reports, management review | | **GDPR** | EU 2016/679 | Articles 5-88 coverage, DSAR management, consent lifecycle | PII registry, processing activity records | Breach notification, DPIA reports | | **CMMC Level 2** | NIST SP 800-171 | 110 practices across 14 domains, SPRS scoring | Automated collectors, POA\&M tracking | Assessment reports, SPRS score history | | **FedRAMP Moderate** | NIST SP 800-53 | 325 controls, continuous monitoring, SSP management | Automated collectors, ConMon reports | Authorization packages, SAR reports | | **HIPAA** | 45 CFR 160-164 | Security Rule safeguards, breach notification, BAA management | PHI access logging, training records | Disclosure reports, risk assessments | | **PCI DSS v4.0** | PCI SSC | 12 requirements, 78 sub-requirements | Automated collectors, control testing | Assessment reports, gap analysis | | **Export Control** | EAR / ITAR | ECCN classification, denied party screening, country controls | Screening logs, license tracking | Transfer reports, compliance dashboards | | **EU AI Act** | EU 2024/1689 | AI system registration, risk assessment, conformity | Incident reports, oversight records | Risk assessments, transparency reports | | **Legal Hold** | FRCP / eDiscovery | Litigation preservation, custodian management | Evidence chain of custody | Hold status reports, compliance verification | ### How Compliance Works in CaseBender Each framework's controls are mapped to CaseBender features and configurations. You can see exactly which platform capabilities satisfy which compliance requirements. Automated collectors gather evidence from the running platform — audit logs, configuration snapshots, access records — without manual effort. Identify which controls are fully implemented, partially implemented, or not yet addressed. Prioritize remediation based on risk. Track audit periods, schedule evidence collection, manage findings, and generate reports for auditors. ## Unified Compliance Dashboard CaseBender provides a unified view across all enabled compliance frameworks: ### Cross-Framework Visibility * **Compliance Score**: Aggregate compliance percentage across all frameworks * **Control Overlap**: Many controls satisfy multiple frameworks simultaneously (e.g., audit logging satisfies SOC2 CC7.2, ISO 27001 A.8.15, CMMC AU.L2-3.3.1, and HIPAA 164.312(b)) * **Gap Prioritization**: Gaps are ranked by how many frameworks they affect * **Deadline Tracking**: Upcoming audit deadlines, evidence collection schedules, and remediation due dates * **Activity Feed**: Recent compliance activities across all frameworks ### Regulatory Reporting * **Automated Report Generation**: Generate framework-specific reports with collected evidence * **Scheduled Reports**: Configure recurring report generation for continuous compliance * **Export Formats**: PDF, CSV, and structured data exports for auditor consumption * **Evidence Packages**: Bundle evidence artifacts with control mappings for audit submissions ## Control Testing CaseBender includes a unified control testing module that works across all frameworks: ### Testing Capabilities * **Automated Tests**: Configurable test procedures that run on schedule * **Manual Tests**: Guided test procedures with evidence capture * **Cross-Framework Mapping**: A single test can satisfy controls across multiple frameworks * **Test Scheduling**: Calendar-based scheduling with reminders and escalation * **Result Tracking**: Pass/fail/partial results with evidence attachment ### Testing Workflow 1. **Schedule**: Tests are scheduled based on framework requirements (quarterly, annually, etc.) 2. **Execute**: Automated tests run automatically; manual tests notify the assigned tester 3. **Evidence**: Test results and supporting evidence are captured automatically 4. **Review**: Results are reviewed and approved by the compliance team 5. **Report**: Test results feed into framework-specific compliance reports ## Compliance Training Track and manage compliance training requirements: * **Training Programs**: Define training requirements per framework and role * **Assignment Management**: Automatically assign training based on user role and team * **Completion Tracking**: Track completion rates, scores, and certification status * **Compliance Matrix**: View training compliance across users, teams, and frameworks * **Campaign Management**: Launch targeted training campaigns for new requirements ## Detailed Framework Documentation Trust Service Criteria, evidence collection, attestation management ISMS controls, risk management, internal audit, Statement of Applicability Data subject rights, consent management, breach notification, cross-border transfers CMMC, FedRAMP, HIPAA, PCI DSS, Export Control, EU AI Act ## Related Documentation * [Audit Logging](/en/security/audit-logging) — The audit trail that provides compliance evidence * [Data Protection](/en/security/data-protection) — Encryption and retention policies * [Security Overview](/en/security/overview) — Platform security posture # SOC2 Type II Source: https://docs.casebender.com/en/security/compliance-soc2 How CaseBender helps you achieve and maintain SOC2 Type II compliance with automated evidence collection and control management. ## Overview CaseBender provides comprehensive SOC2 Type II support, mapping platform capabilities to Trust Service Criteria and automating evidence collection for audit readiness. SOC2 Type II evaluates the operating effectiveness of controls over a period of time (typically 6-12 months), making continuous evidence collection essential. ## Trust Service Criteria Coverage ### Security (Common Criteria) | Control | Description | CaseBender Implementation | | --------------- | --------------------------- | --------------------------------------------------------- | | **CC1.1-CC1.5** | Control Environment | Organization management, team structure, role definitions | | **CC2.1-CC2.3** | Communication & Information | Notification service, audit trail, dashboard reporting | | **CC3.1-CC3.4** | Risk Assessment | Vulnerability management, risk scoring, threat detection | | **CC4.1-CC4.2** | Monitoring Activities | UEBA, security monitoring, compliance dashboards | | **CC5.1-CC5.3** | Control Activities | RBAC, MFA, encryption, input validation | | **CC6.1-CC6.8** | Logical & Physical Access | Authentication, authorization, PAM, API security | | **CC7.1-CC7.5** | System Operations | Audit logging, incident response, change management | | **CC8.1** | Change Management | Version control, deployment pipelines, approval workflows | | **CC9.1-CC9.2** | Risk Mitigation | SLA management, business continuity, disaster recovery | ### Availability | Control | Description | CaseBender Implementation | | -------- | ------------------- | -------------------------------------------------------- | | **A1.1** | Capacity Management | Resource monitoring, auto-scaling support, health checks | | **A1.2** | Recovery Procedures | Backup management, disaster recovery, data retention | | **A1.3** | Recovery Testing | Backup verification, failover testing documentation | ### Confidentiality | Control | Description | CaseBender Implementation | | -------- | ----------------------------- | ---------------------------------------------------- | | **C1.1** | Confidential Information | Data classification, TLP system, access controls | | **C1.2** | Disposal of Confidential Info | Data retention policies, secure deletion, legal hold | ## Evidence Collection ### Automated Collectors CaseBender includes automated evidence collectors that gather compliance artifacts without manual effort: * **Access Control Evidence**: User lists, role assignments, permission matrices, MFA enrollment status * **Audit Log Evidence**: Authentication events, authorization decisions, data access logs, configuration changes * **Change Management Evidence**: Deployment history, code review records, approval workflows * **Encryption Evidence**: Encryption configuration, key rotation history, TLS certificate status * **Monitoring Evidence**: Alert history, incident response records, UEBA anomaly reports ### Collection Schedule | Evidence Type | Frequency | Retention | | ------------------------ | --------- | --------- | | Access reviews | Quarterly | 3 years | | Audit log samples | Monthly | 3 years | | Configuration snapshots | Monthly | 3 years | | Vulnerability scans | Weekly | 3 years | | Penetration test results | Annually | 3 years | | Training records | Quarterly | 3 years | ### Evidence Review Workflow 1. **Collection**: Automated collectors gather evidence on schedule 2. **Review**: Compliance team reviews collected evidence for completeness 3. **Approval**: Evidence is approved and tagged with the relevant control 4. **Storage**: Approved evidence is stored with tamper-evident integrity protection 5. **Retrieval**: Evidence is readily available for auditor review ## Audit Period Management ### Audit Periods * Define audit periods with start and end dates * Track evidence collection progress per period * Monitor control effectiveness across the audit window * Generate period-specific compliance reports ### Gap Analysis CaseBender identifies gaps in your SOC2 compliance: * Controls without sufficient evidence * Controls with outdated evidence * Controls that have not been tested within the required timeframe * New controls introduced by TSC updates that need implementation ### Attestation Management * Track attestation status per control * Record control owner attestations * Manage exception and remediation workflows * Generate attestation reports for auditors ## Reporting ### Audit Reports Generate comprehensive reports for your auditors: * **Control Matrix**: Complete mapping of TSC controls to CaseBender implementations * **Evidence Package**: Bundled evidence artifacts organized by control * **Gap Report**: Outstanding gaps with remediation plans and timelines * **Testing Results**: Control test results with pass/fail status and evidence ### Continuous Monitoring Between formal audits, CaseBender provides continuous compliance monitoring: * Real-time compliance score tracking * Alert on control degradation * Automated evidence collection ensures no gaps accumulate * Dashboard showing audit readiness at any point in time ## Related Documentation * [Compliance Overview](/en/security/compliance-overview) — All supported frameworks * [Audit Logging](/en/security/audit-logging) — The audit trail powering SOC2 evidence * [Access Control](/en/security/access-control) — RBAC and PAM controls # Data Protection Source: https://docs.casebender.com/en/security/data-protection How CaseBender protects your data with encryption, classification, secrets management, and retention policies. ## Encryption ### Data at Rest All data stored by CaseBender is encrypted at rest: * **Database**: PostgreSQL Transparent Data Encryption (TDE) or filesystem-level encryption (dm-crypt/LUKS) * **Field-Level Encryption**: Sensitive fields (API keys, integration credentials, PII) are encrypted at the application level using AES-256-GCM before storage * **Key Versioning**: Encryption keys are versioned, allowing rotation without re-encrypting all data immediately * **Backup Encryption**: Database backups inherit encryption from the underlying storage ### Data in Transit All network communication is encrypted: * **External Traffic**: TLS 1.3 required (TLS 1.2 minimum with AEAD cipher suites only) * **Inter-Service**: Mutual TLS or HMAC-authenticated channels * **Database Connections**: SSL/TLS with certificate verification * **Redis Connections**: TLS with AUTH * **Elasticsearch**: API key authentication over TLS ### Encryption Key Rotation CaseBender supports automated encryption key rotation without downtime: * New key versions are created and activated automatically on schedule * Existing data continues to decrypt with the previous key version * Background re-encryption progressively migrates data to the new key * Progress tracking shows re-encryption status across all encrypted fields * Old key versions are retained until all data is migrated, then securely destroyed ## Data Classification CaseBender includes an automatic data classification engine that categorizes data based on sensitivity: ### Classification Levels | Level | Description | Handling Requirements | | ---------------- | ------------------------------------------------------------------ | ---------------------------------------------------------------------------- | | **Restricted** | Highly sensitive data (credentials, PII, threat actor attribution) | Field-level encryption, strict access control, audit logging on every access | | **Confidential** | Internal security data (case details, investigation notes) | Encrypted storage, role-based access, audit logging | | **Internal** | Operational data (metrics, team assignments, workflow configs) | Standard access controls, periodic review | | **Public** | Non-sensitive data (published CVEs, public advisories) | No special handling required | ### Automatic Classification * **Rule Engine**: Configurable rules that classify entities based on content patterns, source, severity, and TLP level * **Pattern Detection**: Scans for PII patterns (SSN, credit card numbers, email addresses) and auto-classifies accordingly * **TLP Mapping**: TLP classifications automatically map to data classification levels * **Propagation**: Classification levels propagate from parent to child entities (case to alerts, alerts to observables) * **Review Workflow**: Classification changes above a threshold require human review and approval ## Secrets Management CaseBender provides a centralized secrets management system with provider abstraction, so your deployment can use whichever secrets backend your organization standardizes on. ### Supported Providers | Provider | Use Case | Features | | ------------------------- | ------------------------------- | ------------------------------------------------ | | **Environment Variables** | Development, simple deployments | Zero dependencies, easy setup | | **HashiCorp Vault** | Enterprise on-premise | Dynamic secrets, lease management, audit logging | | **AWS Secrets Manager** | AWS deployments | Automatic rotation, cross-region replication | | **Azure Key Vault** | Azure deployments | HSM-backed keys, managed identity integration | | **GCP Secret Manager** | Google Cloud deployments | IAM integration, automatic replication | | **Kubernetes Secrets** | Kubernetes deployments | Native K8s integration, RBAC-controlled | ### Secrets Security Features * **Audit Logging**: Every secret access, creation, update, and deletion is logged with actor identity and timestamp * **Rotation Scheduling**: Automated rotation policies with configurable intervals per secret * **Circuit Breaker**: If a secrets provider becomes unavailable, the system gracefully degrades with cached values and alerts operators * **Retry with Backoff**: Transient failures are retried with exponential backoff before triggering the circuit breaker * **Health Monitoring**: Continuous health checks on secrets providers with alerting on degradation ## Data Retention CaseBender supports configurable data retention policies that comply with multiple regulatory frameworks: ### Jurisdiction-Aware Retention Retention policies are configurable per jurisdiction to meet local regulatory requirements: | Framework | Minimum Retention | Right to Erasure | Legal Basis Required | | ------------------ | ------------------------------- | ---------------- | -------------------- | | **GDPR** | No minimum (purpose limitation) | Yes (Article 17) | Yes | | **SOC2** | 1 year | No | No | | **HIPAA** | 6 years | No | No | | **PCI DSS** | 1 year | No | No | | **SEC Rule 17a-4** | 3-7 years | No | No | | **CMMC** | 3 years | No | No | ### Retention Features * **Policy Engine**: Define retention periods by entity type, classification level, and jurisdiction * **Legal Hold Integration**: Entities under legal hold are exempt from automated deletion regardless of retention policy * **Erasure Requests**: GDPR-compliant right to erasure with verification and audit trail * **Impact Preview**: Before executing retention, preview exactly which entities will be affected * **Automated Execution**: Scheduled retention jobs with full audit logging of every deletion ## Related Documentation * [Security Architecture](/en/security/architecture) — Zero Trust design and service isolation * [Authentication](/en/security/authentication) — How access to data is controlled * [Compliance: GDPR](/en/security/compliance-gdpr) — GDPR-specific data protection features * [Audit Logging](/en/security/audit-logging) — How data access is tracked # Hardening Guide Source: https://docs.casebender.com/en/security/hardening-guide Recommendations for hardening your CaseBender deployment including TLS, database, Redis, container, and monitoring configuration. ## Overview CaseBender ships with secure defaults, but your deployment environment requires additional hardening. This guide provides recommendations for securing the infrastructure surrounding CaseBender. This guide covers infrastructure hardening. CaseBender's application-level security (encryption, RBAC, audit logging) is configured within the application itself. See the relevant security documentation pages for application configuration. ## TLS Configuration ### Reverse Proxy CaseBender should be deployed behind a reverse proxy (Nginx, Caddy, Traefik, or cloud load balancer) that terminates TLS: **Recommended TLS Settings:** | Setting | Value | | ------------------- | -------------------------------------------------- | | Minimum TLS Version | TLS 1.2 (TLS 1.3 preferred) | | Cipher Suites | AEAD ciphers only (AES-256-GCM, ChaCha20-Poly1305) | | HSTS | Enabled with `max-age=31536000; includeSubDomains` | | OCSP Stapling | Enabled | | Certificate Type | RSA 2048+ or ECDSA P-256+ | **Nginx Example:** ```nginx theme={null} ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305; ssl_prefer_server_ciphers on; ssl_session_timeout 1d; ssl_session_cache shared:SSL:10m; ssl_session_tickets off; add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; add_header X-Content-Type-Options "nosniff" always; add_header X-Frame-Options "DENY" always; add_header X-XSS-Protection "1; mode=block" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; ``` ### Certificate Management * Use certificates from a trusted Certificate Authority (Let's Encrypt, DigiCert, etc.) * Automate certificate renewal (certbot, cert-manager) * Monitor certificate expiration with alerting (minimum 30 days before expiry) * Use separate certificates for internal services if implementing mutual TLS ## Database Security ### PostgreSQL Hardening | Setting | Recommendation | | ------------------- | ------------------------------------------------------------------------------- | | **Authentication** | `scram-sha-256` (not `md5` or `trust`) | | **SSL** | Required for all connections (`ssl = on`, `ssl_min_protocol_version = TLSv1.2`) | | **Network** | Listen only on private network interfaces | | **Firewall** | Allow connections only from CaseBender application services | | **Superuser** | Disable remote superuser access | | **Logging** | Enable `log_connections`, `log_disconnections`, `log_statement = 'ddl'` | | **Password Policy** | Minimum 16 characters, rotated quarterly | **pg\_hba.conf Example:** ``` # Reject all by default host all all 0.0.0.0/0 reject # Allow CaseBender services from private network only hostssl casebender casebender_app 10.0.1.0/24 scram-sha-256 ``` ### Backup Security * Encrypt backups at rest (AES-256) * Store backups in a separate location from the primary database * Test backup restoration quarterly * Retain backups according to your compliance requirements (minimum 30 days) * Monitor backup job success/failure with alerting ## Redis Security ### Redis Hardening | Setting | Recommendation | | ---------------------- | ------------------------------------------------------------- | | **Authentication** | `requirepass` with a strong password (32+ characters) | | **TLS** | Enable TLS for all connections (`tls-port` instead of `port`) | | **Network** | Bind to private network interface only (`bind 10.0.1.x`) | | **Dangerous Commands** | Rename or disable `FLUSHALL`, `FLUSHDB`, `CONFIG`, `DEBUG` | | **Max Memory** | Set `maxmemory` with `maxmemory-policy allkeys-lru` | | **Persistence** | Enable AOF persistence for durability | **redis.conf Example:** ``` bind 10.0.1.5 port 0 tls-port 6379 tls-cert-file /etc/redis/tls/redis.crt tls-key-file /etc/redis/tls/redis.key tls-ca-cert-file /etc/redis/tls/ca.crt requirepass YOUR_STRONG_PASSWORD_HERE rename-command FLUSHALL "" rename-command FLUSHDB "" rename-command CONFIG "CONFIG_b4c2e8f1" maxmemory 2gb maxmemory-policy allkeys-lru ``` ## Container Security ### Runtime Hardening If deploying CaseBender with Docker or Kubernetes: **Docker Compose:** ```yaml theme={null} services: web: image: casebender/web:latest read_only: true security_opt: - no-new-privileges:true cap_drop: - ALL tmpfs: - /tmp deploy: resources: limits: cpus: '2.0' memory: 4G reservations: cpus: '0.5' memory: 1G ``` **Kubernetes:** ```yaml theme={null} securityContext: runAsNonRoot: true runAsUser: 1001 readOnlyRootFilesystem: true allowPrivilegeEscalation: false capabilities: drop: - ALL resources: limits: cpu: "2" memory: "4Gi" requests: cpu: "500m" memory: "1Gi" ``` ### Image Verification Before deploying, verify container image signatures: ```bash theme={null} # Verify image signature cosign verify \ --certificate-identity-regexp="github.com/casebender" \ --certificate-oidc-issuer="https://token.actions.githubusercontent.com" \ REGISTRY/casebender/web:TAG # Verify SBOM attestation cosign verify-attestation \ --type cyclonedx \ --certificate-identity-regexp="github.com/casebender" \ --certificate-oidc-issuer="https://token.actions.githubusercontent.com" \ REGISTRY/casebender/web:TAG ``` ## Network Security ### Firewall Rules | Source | Destination | Port | Protocol | Purpose | | ------------- | ----------------- | -------------- | -------- | ------------------- | | Internet | Load Balancer | 443 | HTTPS | User access | | Load Balancer | Web/API/Ingestion | 3000/4000/4100 | HTTP | Application traffic | | App Services | PostgreSQL | 5432 | TCP/TLS | Database | | App Services | Redis | 6379 | TCP/TLS | Cache/Queue | | App Services | Elasticsearch | 9200 | HTTPS | Search | | App Services | SIEM | Varies | TCP/TLS | Audit forwarding | ### Recommendations * Block all inbound traffic except port 443 * Use private networking for all inter-service communication * Implement network segmentation between application and data tiers * Enable network flow logging for forensic analysis * Consider a Web Application Firewall (WAF) in front of the load balancer ## Monitoring ### Health Check Endpoints CaseBender exposes health check endpoints for monitoring: | Endpoint | Purpose | Response | | ----------------------- | --------------------------------------- | -------------------------- | | `/api/health/liveness` | Is the service running? | 200 OK / 503 | | `/api/health/readiness` | Is the service ready to accept traffic? | 200 OK / 503 | | `/api/health/detailed` | Detailed health with dependency status | JSON with component health | ### Recommended Monitoring | Metric | Alert Threshold | Tool | | --------------------- | ---------------------- | ------------------------------- | | Health check failures | 3 consecutive failures | Prometheus, Datadog, CloudWatch | | Response time (P95) | > 2 seconds | APM tool | | Error rate (5xx) | > 1% of requests | Log aggregation | | CPU utilization | > 80% sustained | Infrastructure monitoring | | Memory utilization | > 85% | Infrastructure monitoring | | Disk usage | > 80% | Infrastructure monitoring | | Certificate expiry | \< 30 days | Certificate monitoring | | Backup age | > 24 hours | Backup monitoring | ### Log Aggregation Collect and centralize logs from all CaseBender services: * Application logs (structured JSON) * Access logs (reverse proxy) * Database logs (PostgreSQL) * Redis logs * Container runtime logs Use a log aggregation solution (ELK, Loki, Datadog, Splunk) to centralize, search, and alert on log data. ## Backup and Recovery ### Backup Strategy | Component | Frequency | Retention | Method | | ------------- | ------------------------------- | --------- | --------------------------- | | PostgreSQL | Daily (full) + Continuous (WAL) | 30 days | pg\_dump + WAL archiving | | Redis | Hourly (AOF) | 7 days | AOF persistence + snapshots | | Elasticsearch | Daily | 14 days | Snapshot and restore | | Configuration | On change | 90 days | Version control | ### Recovery Targets | Metric | Target | Description | | ---------------------------------- | ---------- | ---------------------------- | | **RPO** (Recovery Point Objective) | \< 1 hour | Maximum acceptable data loss | | **RTO** (Recovery Time Objective) | \< 4 hours | Maximum acceptable downtime | ### Recovery Testing * Test database restoration quarterly * Test full environment recovery annually * Document recovery procedures and keep them updated * Conduct tabletop exercises for disaster scenarios ## Related Documentation * [Security Architecture](/en/security/architecture) — Platform security design * [Supply Chain Security](/en/security/supply-chain) — Container image verification * [Deployment Overview](/en/deployment/overview) — Platform deployment guides # Security Overview Source: https://docs.casebender.com/en/security/overview CaseBender is built for security teams and secured like one. Explore our enterprise-grade security controls, compliance frameworks, and transparent build pipeline. ## Built for Security Teams, Secured Like One CaseBender is an on-premise case management platform purpose-built for Security Operations Centers. We understand that the tools security teams rely on must meet the same rigorous standards they enforce across their organizations. ### Live Pipeline Status Every code change to CaseBender passes through automated security gates before it reaches a release. These badges reflect real-time CI/CD status from our build pipeline: | Check | Status | What It Covers | | --------------- | ---------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | | Security Scan | ![Security Scan](https://github.com/casebender/webapp/actions/workflows/security-scan.yml/badge.svg?branch=main) | Gitleaks, Trivy, Semgrep SAST, ESLint Security, OWASP ZAP, dependency review, license compliance, SBOM generation | | Supply Chain | ![Supply Chain](https://github.com/casebender/webapp/actions/workflows/supply-chain-verify.yml/badge.svg?branch=main) | Reproducible build verification, lockfile integrity, dependency pinning, image verification | | Image Signing | ![Image Signing](https://github.com/casebender/webapp/actions/workflows/image-sign.yml/badge.svg?branch=main) | Cosign keyless signing for all container images, SBOM attestation | | SLSA Provenance | ![SLSA Provenance](https://github.com/casebender/webapp/actions/workflows/slsa-provenance.yml/badge.svg?branch=main) | SLSA Level 2+ build provenance generation and signing | | Accessibility | ![Accessibility](https://github.com/casebender/webapp/actions/workflows/accessibility-audit.yml/badge.svg?branch=main) | WCAG 2.1 AA, Section 508, ADA Title III compliance | These badges are live and link directly to our CI/CD pipeline. They update automatically with every build. ## Security by the Numbers From Zero Trust architecture to DDoS protection, covering SEC-001 through SEC-020 SOC2, ISO 27001, GDPR, CMMC, FedRAMP, HIPAA, PCI DSS, and more Automated scanning on every commit: SAST, DAST, SCA, secrets, licenses, containers Your data never leaves your infrastructure. No telemetry, no cloud dependencies Every container image is signed with Sigstore. Every build has SLSA provenance Each service image is individually scanned, signed, and attested before release ## Security Principles ### Defense in Depth CaseBender implements multiple layers of security controls. No single control is relied upon in isolation: * **Perimeter**: Rate limiting, DDoS detection, input validation, SSRF prevention * **Authentication**: MFA (TOTP + WebAuthn/FIDO2), SSO (SAML 2.0), step-up authentication * **Authorization**: RBAC, TLP-based access control, privileged access management * **Data**: Encryption at rest (AES-256) and in transit (TLS 1.3), field-level encryption, data classification * **Monitoring**: UEBA behavioral analytics, insider threat detection, unified audit trail, SIEM forwarding * **Supply Chain**: Signed images, SBOM, SLSA provenance, dependency scanning, reproducible builds ### Zero Trust Architecture Every request is verified regardless of origin. CaseBender implements: * Device trust assessment with risk scoring * Mutual service authentication (HMAC) between microservices * Step-up authentication for sensitive operations * Continuous session validation * No implicit trust between services ### On-Premise Advantage As an on-premise platform, CaseBender provides inherent security benefits: * **Data Sovereignty**: Customer data stays within your infrastructure boundary * **Network Control**: You control all ingress and egress * **Air-Gap Support**: Deployable in fully isolated environments * **No Vendor Access**: CaseBender has zero access to your running instance or data * **Compliance Simplification**: Your data classification and retention policies apply directly ## Explore Security Documentation Zero Trust design, service mesh, network segmentation, and multi-tenant isolation Encryption, data classification, TLP system, secrets management, and retention policies MFA, SSO, account lockout, step-up authentication, and WebAuthn/FIDO2 RBAC, privileged access management, cross-team visibility, and API security UEBA, insider threat detection, DDoS protection, and SIEM integration SOC2, ISO 27001, GDPR, CMMC, FedRAMP, HIPAA, PCI DSS, and more Dependency management, container signing, SBOM, SLSA provenance SAST, DAST, vulnerability management, penetration testing, license compliance Unified audit trail, integrity verification, legal hold, e-discovery Deployment hardening, database security, container security, monitoring ## Responsible Disclosure If you discover a security vulnerability in CaseBender, please report it responsibly to [security@casebender.com](mailto:security@casebender.com). We take all reports seriously and will respond within 24 hours. # Supply Chain Security Source: https://docs.casebender.com/en/security/supply-chain How CaseBender secures its build pipeline with dependency management, container signing, SBOM generation, and SLSA provenance. ## Overview CaseBender's supply chain security ensures that every artifact you deploy has been built from verified source code, scanned for vulnerabilities, signed cryptographically, and attested with provenance. These controls run automatically in our CI/CD pipeline — not as optional steps, but as mandatory gates that block releases. ### Live Pipeline Status | Pipeline | Status | Runs On | | ------------------- | --------------------------------------------------------------------------------------------------------------------- | ----------------------------- | | Security Scan | ![Security Scan](https://github.com/casebender/webapp/actions/workflows/security-scan.yml/badge.svg?branch=main) | Every PR and push to main | | Supply Chain Verify | ![Supply Chain](https://github.com/casebender/webapp/actions/workflows/supply-chain-verify.yml/badge.svg?branch=main) | Every PR and push to main | | Image Signing | ![Image Signing](https://github.com/casebender/webapp/actions/workflows/image-sign.yml/badge.svg?branch=main) | Every push to main/production | | SLSA Provenance | ![SLSA Provenance](https://github.com/casebender/webapp/actions/workflows/slsa-provenance.yml/badge.svg?branch=main) | Every push to main/production | ## Dependency Management ### Version Pinning All dependencies are pinned to exact versions to prevent supply chain attacks via version drift: * **`save-exact=true`** in `.npmrc` ensures every `pnpm add` pins to the exact version * **`strict-peer-dependencies=true`** catches incompatible peer dependency versions * **`pnpm install --frozen-lockfile`** in all Dockerfiles ensures builds use exactly the versions in the lockfile * **Node.js version pinned** via `.nvmrc` and `.node-version` (Node.js 20.x) * **pnpm version pinned** in Dockerfiles to prevent tool-level supply chain attacks ### Automated Dependency Updates [Dependabot](https://docs.github.com/en/code-security/dependabot) monitors for updates across three ecosystems: | Ecosystem | Schedule | Scope | | ------------------ | ------------------ | ---------------------------------------------------------- | | **npm** | Weekly (Monday) | Production deps, dev deps, OpenTelemetry, Prisma (grouped) | | **Docker** | Weekly (Tuesday) | Base images for all 7 services | | **GitHub Actions** | Weekly (Wednesday) | All CI/CD workflow action versions | Dependabot PRs are: * Automatically labeled with `dependencies` and `security` * Blocked from merging if they introduce HIGH or CRITICAL vulnerabilities * Reviewed by the security team before merge ### Dependency Review Every pull request is automatically checked for: * New dependencies with known vulnerabilities (HIGH/CRITICAL blocked) * Dependencies with forbidden licenses (copyleft licenses blocked) * Dependencies with no license (flagged for review) * Pre-release dependencies (documented and tracked) ### Approved Component Registry CaseBender maintains a documented registry of approved third-party components organized by risk tier: | Tier | Risk Level | Examples | Review Frequency | | ---------- | ---------- | --------------------------------------- | --------------------- | | **Tier 1** | Critical | next-auth, prisma, bcrypt, jose | Every update reviewed | | **Tier 2** | High | tRPC, zod, bullmq, ioredis | Monthly review | | **Tier 3** | Medium | shadcn/ui, lucide-react, tailwindcss | Quarterly review | | **Tier 4** | Low | eslint, prettier, typescript (dev-only) | Annual review | ## Container Security ### Build Hardening Every CaseBender container image follows security best practices: ``` Multi-Stage Build → Non-Root User → Alpine Base → Pinned Versions → Frozen Lockfile → No Secrets ``` * **Multi-stage builds**: Build dependencies (compilers, dev tools) are excluded from production images * **Non-root users**: Each service runs as a dedicated non-root user inside the container * **Alpine Linux**: Minimal base images reduce attack surface * **Pinned tool versions**: System packages and global tools are version-pinned * **No embedded secrets**: All secrets are injected at runtime ### Container Scanning Every container image is scanned with [Trivy](https://trivy.dev/) for: * **OS vulnerabilities**: CVEs in Alpine packages * **Application vulnerabilities**: CVEs in Node.js dependencies * **Misconfigurations**: Dockerfile best practice violations * **Secrets**: Embedded credentials or API keys Scans run on every PR and block merges if CRITICAL or HIGH vulnerabilities are found. ## Image Signing All 7 CaseBender container images are cryptographically signed using [Cosign](https://docs.sigstore.dev/cosign/overview/) with keyless signing via [Sigstore](https://www.sigstore.dev/): ### Signed Images | Image | Registry | | ------------------------------- | ------------------------ | | `casebender/web` | Google Artifact Registry | | `casebender/api` | Google Artifact Registry | | `casebender/ingestion` | Google Artifact Registry | | `casebender/worker` | Google Artifact Registry | | `casebender/workflow-processor` | Google Artifact Registry | | `casebender/misp-processor` | Google Artifact Registry | | `casebender/search-sync` | Google Artifact Registry | ### Verification Before deployment, our CI/CD pipeline verifies: 1. **Signature Verification**: Cosign verifies the image signature against the Sigstore transparency log 2. **SBOM Attestation**: Verifies that a signed SBOM is attached to the image 3. **Vulnerability Scan**: Final Trivy scan for CRITICAL vulnerabilities 4. **Provenance Check**: Verifies SLSA provenance attestation exists You can verify any CaseBender image signature yourself using: ```bash theme={null} cosign verify --certificate-identity-regexp="github.com/casebender" \ --certificate-oidc-issuer="https://token.actions.githubusercontent.com" \ REGISTRY/casebender/web:TAG ``` ## SBOM (Software Bill of Materials) Every release includes a signed Software Bill of Materials in [CycloneDX](https://cyclonedx.org/) format: * **Generated by**: Trivy SBOM scanner * **Format**: CycloneDX JSON * **Signed with**: Cosign (keyless via Sigstore) * **Attached to**: Each container image as an attestation * **Retention**: 3 years (aligned with compliance requirements) The SBOM documents every component in the container image: * Node.js runtime version * All npm packages with exact versions * Alpine Linux packages * System libraries and their versions ## SLSA Provenance CaseBender generates [SLSA](https://slsa.dev/) Level 2+ build provenance for every release: ### What Provenance Documents | Field | Content | | ---------------- | ------------------------------------------- | | **Source** | Git commit SHA, repository URL, branch | | **Builder** | GitHub Actions workflow, runner environment | | **Build Config** | Workflow file path, trigger event | | **Artifacts** | Container image digests for all 7 services | | **Metadata** | Build timestamp, actor, invocation ID | ### Provenance Security * Provenance documents are signed with Cosign (keyless via Sigstore) * Signatures are verified after generation * Provenance is retained for 3 years * Provenance can be independently verified against the Sigstore transparency log ## Pre-Deployment Verification Before any deployment, two verification scripts run as mandatory gates: ### Reproducible Build Verification Checks that the build environment is consistent and secure: * Lockfile integrity (`pnpm-lock.yaml` exists and is valid) * Node.js version matches expected version (20.x) * pnpm version matches expected version (9.15.0) * `.npmrc` security settings are present (`save-exact`, `audit`) * No suspicious postinstall scripts in dependencies * Version pinning files (`.nvmrc`, `.node-version`) are present ### Image Verification Checks that container images are authentic and safe: * Cosign signature verification for each image * SBOM attestation verification * Trivy vulnerability scan (CRITICAL severity) * Image provenance check ## Compliance Mapping | Control | Framework | CaseBender Implementation | | ---------------------------- | ----------- | ----------------------------------------------------------- | | SR-3 Supply Chain Protection | CMMC | Dependency pinning, lockfile integrity, reproducible builds | | SR-4 Provenance | CMMC | SLSA provenance, image signing, SBOM | | SR-11 Component Authenticity | CMMC | Cosign signature verification, Sigstore transparency | | SI-7 Software Integrity | NIST 800-53 | Image signing, SBOM attestation, build verification | | CM-2 Baseline Configuration | NIST 800-53 | Pinned versions, frozen lockfiles, reproducible builds | | CM-6 Configuration Settings | NIST 800-53 | `.npmrc` hardening, Dockerfile best practices | ## Related Documentation * [Code Security](/en/security/code-security) — SAST, DAST, and vulnerability management * [Security Overview](/en/security/overview) — Live pipeline status badges * [Hardening Guide](/en/security/hardening-guide) — Deployment security recommendations # AI Settings Source: https://docs.casebender.com/en/settings/ai/introduction Configure and manage AI providers to enable intelligent features in your CaseBender instance. ## Overview The AI Settings section allows you to configure various AI providers to enhance your CaseBender experience with intelligent features. This includes setting up providers like OpenAI, Anthropic, and others to power features such as case analysis, content generation, and automated processing. AI Settings Dashboard Light AI Settings Dashboard Dark ## Configuring AI Providers ### Step 1: Enable Provider To start using an AI provider, locate the provider card in the dashboard and toggle the enable switch: Enable AI Provider Light Enable AI Provider Dark The configuration modal will appear where you can: * Enter your API key * Configure basic settings * Set usage limits * Define access permissions ### Step 2: Model Selection After entering a valid API key, you'll see available models for the provider: Model Selection Light Model Selection Dark Configure model-specific settings: * Select preferred models * Set model-specific parameters * Configure usage quotas * Define model access permissions ### Step 3: Provider Configuration Complete Once configured, the provider card will show its active status and configuration details: Configured Provider Light Configured Provider Dark The configured provider card displays: * Active status * Selected models * Usage statistics * Quick access to settings ## Available Providers ### OpenAI * GPT-4 and GPT-3.5 models * Text generation and analysis * Code assistance * Data extraction ### Anthropic * Claude and Claude 2 models * Advanced reasoning * Document analysis * Complex task handling ### Deepseek * Deepseek-coder models * Code generation and analysis * Technical documentation * Programming assistance ### Azure OpenAI * Managed OpenAI services * Enterprise security features * Regional availability * Dedicated resources ### Groq * LPU inference * Ultra-fast processing * High-performance models * Low-latency responses ### Google AI * PaLM and Gemini models * Multi-modal capabilities * Advanced language understanding * Enterprise-grade reliability ### xAI * Grok models * Real-time knowledge integration * Conversational AI * Context-aware responses ### Ollama * Local model deployment * Custom model support * Offline processing * Resource-efficient inference ## Best Practices ### Security * Securely store API keys * Regularly rotate credentials * Monitor API usage * Set appropriate access controls ### Cost Management * Configure usage limits * Monitor token consumption * Set model-specific quotas * Track usage patterns ### Performance * Choose appropriate models * Optimize prompt engineering * Monitor response times * Configure timeout settings ### Maintenance * Regularly verify provider status * Update API keys before expiration * Monitor model availability * Keep configurations current ## Features Enabled by AI ### Case Management * Automated case analysis * Content summarization * Priority assessment * Related case identification ### Document Processing * Text extraction * Document classification * Content analysis * Key information highlighting ### Workflow Automation * Intelligent routing * Content generation * Decision support * Pattern recognition ## Related Documentation * [AI Features](../../cases/ai-features.mdx) # Alert Statuses Source: https://docs.casebender.com/en/settings/alert-statuses/introduction Configure and manage custom alert statuses to track the lifecycle of alerts in your security operations. ## Overview The Alert Statuses section allows you to create and manage custom status definitions for your alerts. This feature helps you track the progression of alerts through your security operations workflow, from initial detection to final resolution. Alert Statuses Dashboard Light Alert Statuses Dashboard Dark ## Managing Alert Statuses ### Creating a New Status Click the "Create" button to add a new alert status: Create Alert Status Form Light Create Alert Status Form Dark Configure the basic status information: * Status name * Description * Color indicator * Icon selection * Category ### Configuring Status Details Provide comprehensive configuration for your alert status: Alert Status Configuration Light Alert Status Configuration Dark Define detailed settings: * Status behavior * Automation rules * Notification settings * Access permissions ### Status Management View and manage your configured alert statuses: Alert Status List Light Alert Status List Dark The status list displays: * Status name and icon * Description * Category * Creation date * Last modified * Actions ## Default Status Types ### New Alerts * New * Unassigned * Assigned * In Progress ### Investigation * Under Investigation * Needs Information * Awaiting Response * On Hold ### Resolution * Resolved * Closed * False Positive * Duplicate ### Escalation * Escalated * Critical * Requires Attention * Pending Review ## Status Configuration ### Visual Indicators * Color coding * Icon selection * Status badges * Priority markers ### Behavior Settings * Auto-transition rules * Time-based triggers * Required fields * Status dependencies ### Access Control * Role-based access * Team permissions * Status restrictions * Modification rights ## Best Practices ### Status Design * Use clear, descriptive names * Maintain consistent naming * Choose intuitive colors * Select appropriate icons ### Workflow Integration * Define logical progression * Set up automation rules * Configure notifications * Enable tracking ### Organization * Group related statuses * Define clear categories * Set proper ordering * Maintain hierarchy ### Maintenance * Review status usage * Update as needed * Remove unused statuses * Document changes ## Using Alert Statuses ### In Alert Management * Track alert lifecycle * Monitor progress * Manage workload * Measure response time ### In Reporting * Status distribution * Resolution metrics * Team performance * Response analytics ### In Automation * Status-based triggers * Automatic updates * Notification rules * Workflow automation # Attack Patterns Source: https://docs.casebender.com/en/settings/attack-patterns/introduction Browse and manage MITRE ATT&CK patterns to enhance your threat detection and response capabilities. ## Overview The Attack Patterns section provides access to a comprehensive library of MITRE ATT\&CK patterns, enabling you to understand, track, and defend against various cyber attack techniques. This knowledge base helps in identifying, categorizing, and responding to security threats effectively. Attack Patterns Dashboard Light Attack Patterns Dashboard Dark ## Understanding Attack Patterns ### Pattern Categories * Initial Access * Execution * Persistence * Privilege Escalation * Defense Evasion * Credential Access * Discovery * Lateral Movement * Collection * Command and Control * Exfiltration * Impact ### Pattern Information Each attack pattern entry includes: * Technique ID (e.g., T1234) * Technique Name * Tactic Category * Description * Sub-techniques * Detection Methods * Mitigation Strategies ## Using Attack Patterns ### Threat Analysis * Identify attack techniques * Map threat actor behaviors * Analyze attack chains * Assess risk levels ### Incident Response * Classify incidents * Guide investigation * Determine scope * Plan remediation ### Threat Hunting * Create hunt hypotheses * Define search patterns * Identify indicators * Track progression ## Integration Features ### Case Management * Link patterns to cases * Document observed techniques * Track attack progression * Map incident timeline ### Threat Intelligence * Correlate with known threats * Map actor behaviors * Identify emerging patterns * Share intelligence ### Reporting * Generate attack summaries * Create pattern analytics * Track pattern frequency * Measure effectiveness ## Best Practices ### Pattern Analysis * Review pattern details * Understand prerequisites * Identify dependencies * Map related techniques ### Implementation * Document observed patterns * Link to incidents * Track effectiveness * Update procedures ### Maintenance * Keep patterns current * Review classifications * Update documentation * Monitor trends ### Team Training * Share pattern knowledge * Practice identification * Review case studies * Update procedures ## MITRE ATT\&CK Framework ### Framework Overview * Enterprise Matrix * Mobile Matrix * ICS Matrix * Cloud Matrix ### Tactics Categories * Why attackers use them * Common implementations * Detection strategies * Mitigation approaches ### Techniques & Sub-techniques * Detailed descriptions * Implementation examples * Detection methods * Mitigation strategies ## Related Documentation * [Case Management](../../cases/introduction.mdx) # Branding Source: https://docs.casebender.com/en/settings/branding/introduction Customize the look and feel of your CaseBender instance with your organization's branding elements. ## Overview The Branding section allows you to customize the visual appearance of your CaseBender instance to match your organization's brand identity. You can configure colors, logos, and other visual elements to create a consistent and professional look across your security operations platform. Branding Dashboard Light Branding Dashboard Dark ## Brand Elements ### Primary Colors Configure your organization's primary color scheme: Primary Colors Light Primary Colors Dark Customize the following color elements: * Primary brand color * Secondary colors * Accent colors * Background colors * Text colors ## Customization Options ### Logo Settings * Upload organization logo * Set logo dimensions * Configure placement * Define visibility rules * Dark/light mode variants ### Color Scheme * Primary colors * Secondary palette * System status colors * Alert level indicators * Background gradients ### Typography * Font family selection * Text sizes * Font weights * Line heights * Letter spacing ### UI Elements * Button styles * Form elements * Card designs * Navigation items * Modal windows ## Theme Configuration ### Light Mode * Background colors * Text colors * UI element colors * Contrast settings * Accessibility options ### Dark Mode * Dark theme colors * Text visibility * Element contrast * Shadow effects * Accent highlights ### System Elements * Navigation bar * Sidebar * Headers * Footers * Action buttons ## Best Practices ### Brand Consistency * Follow brand guidelines * Maintain color harmony * Ensure readability * Consider accessibility * Test across devices ### Visual Hierarchy * Emphasize important elements * Create clear contrast * Use consistent spacing * Implement proper scaling * Maintain balance ### Accessibility * Color contrast ratios * Text readability * Screen reader support * Keyboard navigation * Focus indicators ### Performance * Optimize image sizes * Minimize CSS * Cache resources * Load time considerations * Responsive design ## Implementation Guide ### Basic Setup 1. Upload brand assets 2. Configure primary colors 3. Set typography 4. Adjust UI elements 5. Test appearance ### Advanced Configuration 1. Custom CSS rules 2. Component overrides 3. Theme variations 4. Responsive adjustments 5. Animation settings ### Testing 1. Cross-browser testing 2. Device compatibility 3. Accessibility validation 4. Performance checks 5. User feedback # Case Statuses Source: https://docs.casebender.com/en/settings/case-statuses/introduction Configure and manage custom case statuses to track the lifecycle of cases in your security operations. ## Overview The Case Statuses section enables you to create and manage custom status definitions for your cases. This feature helps you track the progression of cases through your incident response and investigation workflow, ensuring consistent case management across your organization. Case Statuses Dashboard Light Case Statuses Dashboard Dark ## Managing Case Statuses ### Creating a New Status Click the "Create" button to add a new case status: Create Case Status Form Light Create Case Status Form Dark Configure the basic status information: * Status name * Description * Color indicator * Icon selection * Category/Phase ### Configuring Status Details Provide comprehensive configuration for your case status: Case Status Configuration Light Case Status Configuration Dark Define detailed settings: * Status behavior * Workflow rules * Required fields * Team permissions ### Status Management View and manage your configured case statuses: Case Status List Light Case Status List Dark The status list displays: * Status name and icon * Description * Phase/Category * Creation date * Last modified * Actions ## Default Status Types ### Initial Phase * New * Opened * Assigned * Triaged ### Investigation Phase * Under Investigation * Evidence Collection * Analysis in Progress * Pending Information ### Action Phase * Containment * Eradication * Recovery * Remediation ### Closure Phase * Resolved * Closed * Archived * Reopened ## Status Configuration ### Visual Elements * Status colors * Icon selection * Phase indicators * Priority badges ### Workflow Rules * Status transitions * Required actions * Time limits * Dependencies ### Field Requirements * Mandatory fields * Optional information * Documentation needs * Approval requirements ## Best Practices ### Status Design * Clear naming conventions * Logical progression * Consistent terminology * Intuitive organization ### Process Integration * Align with procedures * Define clear transitions * Set completion criteria * Enable tracking ### Team Collaboration * Role assignments * Handoff procedures * Communication rules * Responsibility matrix ### Quality Control * Regular reviews * Status audits * Process validation * Effectiveness metrics ## Using Case Statuses ### In Case Management * Track investigation progress * Monitor response actions * Manage resources * Ensure compliance ### In Workflow Automation * Status-based triggers * Automatic assignments * Notification rules * SLA tracking ### In Reporting * Case metrics * Resolution times * Team performance * Trend analysis ## Related Documentation * [Case Management](../../cases/introduction.mdx) # Custom Fields Source: https://docs.casebender.com/en/settings/custom-fields/introduction Create and manage custom fields to extend your case management capabilities in CaseBender. ## Overview The Custom Fields section allows you to create and manage additional fields that can be used across your cases and tasks. This feature enables you to customize your data collection and organization according to your specific needs. Custom Fields Dashboard Light Custom Fields Dashboard Dark ## Creating Custom Fields ### Step 1: Initialize Creation Click the "Create" button to start creating a new custom field: Create Custom Field Form Light Create Custom Field Form Dark Fill out the basic information: * Field name * Description * Category * Required status * Visibility settings ### Step 2: Select Field Type Choose the appropriate field type for your data: Field Types Selection Light Field Types Selection Dark Available field types include: * Text (Single line) * Text Area (Multi-line) * Number * Date * Select (Single choice) * Multi-select * Checkbox * Radio buttons * URL * Email * Phone number ### Step 3: Field Configuration Complete After creation, the field will appear in the custom fields table: Dashboard with Custom Field Light Dashboard with Custom Field Dark The table displays: * Field name * Type * Category * Required status * Creation date * Last modified date * Actions ## Field Types and Use Cases ### Text Fields * Single line: Short text responses * Text area: Detailed descriptions * Rich text: Formatted content ### Numeric Fields * Numbers: Quantities, measurements * Currency: Financial values * Percentage: Ratios, completion rates ### Selection Fields * Dropdown: Single choice from options * Multi-select: Multiple choices * Radio buttons: Exclusive choices * Checkboxes: Yes/No options ### Special Fields * Date/Time: Temporal information * URL: Web links * Email: Contact information * Phone: Contact numbers ## Best Practices ### Field Design * Use clear, descriptive names * Provide helpful descriptions * Choose appropriate field types * Set sensible default values ### Organization * Group related fields * Maintain consistent naming * Use categories effectively * Consider field order ### Validation * Set appropriate constraints * Define required fields * Configure format validation * Test field behavior ### Maintenance * Review field usage * Update obsolete fields * Document changes * Monitor performance impact ## Using Custom Fields ### In Cases * Add to case forms * Use in case views * Include in reports * Filter and sort ### In Tasks * Task creation forms * Task details * Progress tracking * Completion criteria ### In Reports * Data analysis * Custom metrics * Export options * Dashboard integration ## Related Documentation * [Case Management](../../cases/introduction.mdx) * [Task Management](../../tasks/introduction.mdx) # Integrations Source: https://docs.casebender.com/en/settings/integrations/introduction Configure and manage integrations with external services and systems in your CaseBender instance. ## Overview The Integration Settings section allows you to manage and create integrations with various external services to enhance your CaseBender workflow. This guide will walk you through the process of setting up new integrations. Integration Dashboard Light Integration Dashboard Dark ## Creating a New Integration ### Step 1: Select Integration Type From the dashboard, click the "Create" button to see available integration options: Available Integrations Light Available Integrations Dark ### Step 2: Basic Configuration After selecting an integration type, you'll be presented with the integration configuration form: Integration Form Light Integration Form Dark Fill out the required information such as: * Integration name * Description * Basic configuration options * Connection details ### Step 3: Advanced Settings Configure additional settings specific to your integration type: Configured Form Light Configured Form Dark ### Step 4: Organization Settings Specify which organizations can access this integration: Organization Settings Light Organization Settings Dark * Select applicable organizations * Set organization-specific configurations * Define access levels and permissions ### Step 5: Final Configuration After clicking the Continue button, complete the final configuration steps: Final Configuration Light Final Configuration Dark * Configure advanced features * Set up authentication details * Review and verify settings * Test the connection ## Best Practices ### Setting Up Integrations * Choose meaningful names for easy identification * Provide detailed descriptions for future reference * Test connections before finalizing * Document custom configurations ### Security Considerations * Use secure credentials * Implement proper access controls * Regular security audits * Monitor integration usage ### Maintenance * Regularly verify integration status * Update configurations as needed * Monitor performance metrics * Keep documentation current # Microsoft Defender XDR Source: https://docs.casebender.com/en/settings/integrations/microsoft-defender Bi-directional integration between CaseBender and Microsoft Defender XDR (Windows Defender) for alert/incident ingestion and disposition sync. ## Overview The Microsoft Defender XDR integration (**INT-021**) provides **bi-directional** synchronization between CaseBender and Microsoft's extended detection and response platform, including **Microsoft Defender for Endpoint (MDE)** and **Microsoft Defender XDR**. Defender alerts and incidents are ingested into CaseBender, normalized, enriched with observables and MITRE ATT\&CK techniques, and turned into alerts/cases. When a CaseBender case is closed, the linked Defender alert/incident is updated with the matching status, classification, and an audit comment via Microsoft Graph. This integration uses the **Microsoft Graph Security API** (`https://graph.microsoft.com/v1.0/security`). It authenticates with an **Azure AD (Entra ID) application** using the OAuth2 client-credentials flow. ## Capabilities | Capability | Direction | Description | | ------------------------- | -------------- | -------------------------------------------------------------------------------------------- | | Alert ingestion | Inbound | Defender alerts are normalized into CaseBender alerts | | Incident ingestion | Inbound | Defender incidents (with child alerts) are ingested | | Observable extraction | Inbound | IPs, URLs, file hashes, file names, hostnames, and user accounts are extracted from evidence | | Asset extraction | Inbound | Device hostname, IP, and OS platform are captured from `devices[]` | | MITRE ATT\&CK correlation | Inbound | Technique IDs are added as tags and TTPs (e.g. `mitre:T1078`) | | Alert disposition sync | Outbound | Alert `status`, `classification`, `determination`, and comments are pushed on case close | | Incident disposition sync | Outbound | Incident `status`, `classification`, `determination`, and comments are pushed on case close | | Connection test | Bi-directional | Validates OAuth2 credentials and Graph Security API access | ## Prerequisites A Microsoft Entra ID (Azure AD) tenant with Microsoft Defender XDR or Microsoft Defender for Endpoint licensed and enabled. You need permission to register applications and grant admin consent. The CaseBender deployment must be able to reach: * `https://login.microsoftonline.com` (OAuth2 token endpoint) * `https://graph.microsoft.com` (Graph Security API) You must be able to create and manage integrations in **Settings → Integrations**. ## Part A — Register an Azure AD application In the [Microsoft Entra admin center](https://entra.microsoft.com), go to **Identity → Applications → App registrations → New registration**. Give it a name (e.g. `CaseBender Defender Integration`) and register it. From the application **Overview**, copy the **Application (client) ID** and the **Directory (tenant) ID**. You will enter these into CaseBender. Under **Certificates & secrets → New client secret**, create a secret and copy its **Value** immediately (it is only shown once). Under **API permissions → Add a permission → Microsoft Graph → Application permissions**, add the following and then click **Grant admin consent**: | Permission | Purpose | | -------------------------------- | ---------------------------------- | | `SecurityAlert.ReadWrite.All` | Read and update Defender alerts | | `SecurityIncident.ReadWrite.All` | Read and update Defender incidents | Use **Application** permissions (not Delegated). The integration runs headless with the client-credentials flow and requires tenant admin consent. ## Part B — Configure the integration in CaseBender Go to **Settings → Integrations → Create**, then choose **Microsoft Defender XDR** from the **EDR/XDR** category. Provide the values captured in Part A: | Field | Description | | -------------- | ----------------------- | | `tenantId` | Directory (tenant) ID | | `clientId` | Application (client) ID | | `clientSecret` | Client secret value | Enable the behaviors you need: | Option | Effect | | --------------------------- | ----------------------------------------------------------- | | `syncCaseClose` | Push case closure back to Defender | | `autoCreateCases` | Automatically create cases from ingested Defender incidents | | `closeAlertsOnCaseClose` | Resolve the linked Defender **alert** when a case closes | | `closeIncidentsOnCaseClose` | Resolve the linked Defender **incident** when a case closes | Use **Test Connection** to validate. CaseBender requests an OAuth2 token and calls `GET /security/alerts_v2?$top=1`. A `403` response during the test is treated as **success** — it confirms authentication worked even when the app has not yet been granted read scope on that specific endpoint. ## Inbound: Ingesting Defender alerts and incidents ### Endpoint Defender (or an intermediary such as Logic Apps, Sentinel, or a webhook forwarder) sends alert/incident payloads to the CaseBender ingestion endpoint: ``` POST https:///api/v1/ingest/defender ``` Requests are authenticated with an integration **API key** passed in the `x-api-key` header (the `authorization: Bearer ` header is also accepted). Defender webhook API keys are prefixed with `cbr_defender_`. ### Payload formats Both a **batch** format (Graph `value[]` array) and a **single alert** object are supported. ```bash Batch (Graph value[]) theme={null} curl -X POST "https:///api/v1/ingest/defender" \ -H "x-api-key: cbr_defender_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \ -H "Content-Type: application/json" \ -d '{ "value": [ { "id": "da637...", "incidentId": "12345", "title": "Suspicious PowerShell execution", "severity": "high", "status": "new", "classification": "unknown", "createdDateTime": "2026-07-03T18:20:00Z", "mitreTechniques": ["T1059.001"], "evidence": [ { "@odata.type": "#microsoft.graph.security.fileEvidence", "sha256": "9f2b...", "fileName": "payload.ps1" } ] } ] }' ``` ```bash Single alert theme={null} curl -X POST "https:///api/v1/ingest/defender" \ -H "x-api-key: cbr_defender_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \ -H "Content-Type: application/json" \ -d '{ "id": "da637...", "title": "Malware detected on endpoint", "severity": "medium", "status": "new", "createdDateTime": "2026-07-03T18:20:00Z" }' ``` A successful request returns HTTP `202 Accepted`: ```json theme={null} { "success": true, "processed": 1, "failed": 0 } ``` ### Processing pipeline The payload flows through CaseBender's ingestion services: `/api/v1/ingest/defender` validates the source and forwards the request to the ingestion service (`POST /v1/sources/defender`). The ingestion service authenticates the API key, validates the payload, and publishes each alert to the processing queue. The Defender processor normalizes each record into a CaseBender alert — mapping severity, building the title/description, extracting observables and device assets, and generating MITRE TTPs. ### Data mapping reference **Severity mapping** (Defender → CaseBender 1–4): | Defender severity | CaseBender severity | | ----------------- | ------------------- | | `high` | 1 | | `medium` | 2 | | `low` | 3 | | `informational` | 4 | | `unknown` | 3 | **Observable extraction** (from `evidence[]`): | Evidence field | Observable type | | --------------- | ------------------------- | | `ipAddress` | `ip` | | `url` | `url` | | `sha256` | `hash` | | `fileName` | `filename` | | `deviceDnsName` | `hostname` | | `userAccount` | `user` (`DOMAIN\account`) | **Tags** applied on ingest include `defender`, `xdr`, `service:`, `category:`, `incident` (for incidents), and one `mitre:` tag per MITRE technique. Ingested records default to **TLP:2** and **PAP:2**. ## Outbound: Syncing case dispositions to Defender When a case is closed in CaseBender, the `case_closed` event is dispatched to the Defender handler. If the case is linked to a Defender alert or incident, CaseBender pushes the resolution back through the Graph Security API. ### How the linked Defender entity is resolved The handler looks for the Defender identifiers in this order: 1. `extraData.defenderAlertId` / `extraData.defenderIncidentId` 2. `sourceRef` when `extraData.source === "defender"` 3. `sourceRef` when it looks like a Defender alert reference (prefix `da`) If no alert or incident ID is found, the case close is skipped for this integration. ### Resolution → classification mapping | CaseBender resolution | Defender classification | | --------------------- | ------------------------------- | | `TruePositive` | `truePositive` | | `FalsePositive` | `falsePositive` | | `Duplicate` | `informationalExpectedActivity` | | `NoImpact` | `informationalExpectedActivity` | | *(other / none)* | `truePositive` (default) | On close, CaseBender sets the alert/incident `status` to `resolved`, applies the mapped `classification`, and adds a comment such as: ``` Case closed in CaseBender with resolution: ``` Outbound alert updates require `closeAlertsOnCaseClose` to be enabled; incident updates require `closeIncidentsOnCaseClose`. If neither is enabled, no outbound sync occurs. ## Security considerations * **Secret handling** — the client secret is stored in the integration settings; rotate it on the schedule your organization requires and update the integration when you do. * **Least privilege** — grant only `SecurityAlert.ReadWrite.All` and `SecurityIncident.ReadWrite.All`. Do not add broader Graph scopes. * **Token caching** — access tokens are cached in memory per integration and refreshed one minute before expiry; no tokens are persisted to disk. * **Webhook keys** — treat the `cbr_defender_` API key as a secret. Rotate it if exposed and update the sender configuration. * **Network** — restrict egress to `login.microsoftonline.com` and `graph.microsoft.com`. ## Troubleshooting Verify the `tenantId`, `clientId`, and `clientSecret`. Confirm the client secret has not expired and that admin consent was granted for the Graph application permissions. The `x-api-key` header is missing or invalid. Confirm you are sending the `cbr_defender_` key that matches the integration's configured webhook API key. The payload had neither a `value[]` array nor a top-level `id`. Send a Graph batch object or a single alert object. Ensure `closeAlertsOnCaseClose` / `closeIncidentsOnCaseClose` is enabled and that the case carries a Defender alert/incident ID (via `extraData` or `sourceRef`). The Azure AD app lacks write permission. Confirm `SecurityAlert.ReadWrite.All` and `SecurityIncident.ReadWrite.All` are granted with admin consent. ## Related documentation * [Integrations overview](./introduction.mdx) * [Microsoft Graph Security API](https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview) * [Microsoft Defender XDR](https://learn.microsoft.com/en-us/defender-xdr/) # Introduction Source: https://docs.casebender.com/en/settings/introduction Configure and customize your CaseBender environment with comprehensive system settings and preferences. ## Overview The Settings section provides complete control over your CaseBender environment configuration: !\[Settings Dashboard] *Screenshot showing the main settings dashboard* ## Available Settings ### System Configuration * **Authentication**: Configure authentication methods and security settings * **Branding**: Customize your instance's look and feel * **License**: Manage your license and subscription ### Workflow Settings * **Alert Statuses**: Configure alert status workflows * **Case Statuses**: Manage case status definitions * **Templates**: Create and manage templates * **Workflows**: Define automated workflows ### Data Management * **Custom Fields**: Define custom fields for various entities * **Observable Types**: Configure observable type definitions * **Attack Patterns**: Manage MITRE ATT\&CK® patterns ### Integration Settings * **AI Configuration**: Set up AI features and preferences * **Controllers**: Configure external system controllers * **Integrations**: Manage third-party integrations ## Access Control Settings access is controlled by: * User roles * Permission levels * Organization settings * Admin privileges ## Best Practices ### 1. Configuration Management * Document changes * Test in staging * Regular review * Backup settings ### 2. Access Control * Limit admin access * Audit changes * Define clear roles * Regular review ### 3. Maintenance * Regular updates * Performance monitoring * Security checks * Backup verification ## Next Sections * [Workflow Settings](./workflows/introduction.mdx) * [Integration Settings](./integrations/introduction.mdx) # Observable Types Source: https://docs.casebender.com/en/settings/observable-types/introduction Configure and manage observable types to categorize and track different types of indicators in your threat intelligence. ## Overview The Observable Types section allows you to define and manage different types of observables that can be tracked in your threat intelligence operations. These types help categorize various indicators such as IP addresses, domains, file hashes, and other digital artifacts that you monitor. Observable Types Dashboard Light Observable Types Dashboard Dark ## Managing Observable Types ### Creating a New Type Click the "Create" button to add a new observable type: Create Observable Type Form Light Create Observable Type Form Dark Configure the following settings: * Type name * Description * Category * Validation rules * Display format ## Common Observable Types ### Network Indicators * IP Address * IPv4 format * IPv6 format * CIDR notation * Domain Names * Fully Qualified Domain Names (FQDN) * Wildcards * IDN support * URLs * Web addresses * URI patterns * Protocol specifications ### File Indicators * File Hashes * MD5 * SHA-1 * SHA-256 * SHA-512 * File Names * Extensions * Patterns * Regular expressions * File Paths * Directory structures * Path patterns ### System Indicators * Registry Keys * Windows registry paths * Value names * Data types * Process Names * Executable names * Command lines * Process patterns * Service Names * Windows services * Unix daemons * Service patterns ### Communication Indicators * Email Addresses * Address formats * Domain validation * Pattern matching * User Accounts * Usernames * Account IDs * Platform identifiers * Communication Protocols * Port numbers * Protocol identifiers * Service definitions ## Best Practices ### Type Definition * Use clear, descriptive names * Provide detailed descriptions * Set appropriate validation rules * Include example values ### Organization * Group related types * Maintain consistent naming * Use categories effectively * Consider type relationships ### Validation Rules * Define format requirements * Set value constraints * Configure pattern matching * Implement data validation ### Maintenance * Review type usage * Update definitions * Document changes * Monitor effectiveness ## Using Observable Types ### In Cases * Threat indicators * IOC tracking * Evidence collection * Pattern matching ### In Analysis * Indicator correlation * Pattern detection * Threat hunting * Intelligence gathering ### In Reports * Indicator statistics * Type distribution * Trend analysis * Intelligence reporting ## Related Documentation * [Case Management](../../cases/introduction.mdx) # Templates Source: https://docs.casebender.com/en/settings/templates/introduction Create and manage templates to standardize case creation and response procedures in your security operations. ## Overview The Templates section allows you to create and manage predefined templates for various aspects of your security operations. Templates help ensure consistency, save time, and standardize processes across your organization by providing ready-to-use configurations for cases, tasks, and workflows. Templates Dashboard Light Templates Dashboard Dark ## Managing Templates ### Creating a New Template Click the "Create" button to start creating a new template: Create Template Form Light Create Template Form Dark Configure the basic template information: * Template name * Description * Category * Type (Case/Task/Workflow) * Access permissions ### Configuring Template Details Define the comprehensive configuration for your template: Template Configuration Light Template Configuration Dark Specify detailed settings: * Content structure * Default values * Required fields * Automation rules * Team assignments ### Template Management View and manage your configured templates: Template List Light Template List Dark The template list displays: * Template name * Description * Category * Type * Usage count * Last modified * Actions ## Template Types ### Case Templates * Incident Response * Threat Hunting * Vulnerability Management * Security Assessment * Compliance Review ### Task Templates * Investigation Steps * Evidence Collection * Analysis Procedures * Remediation Actions * Status Updates ### Workflow Templates * Alert Triage * Incident Response * Threat Investigation * Compliance Checks * Regular Assessments ## Template Components ### Content Structure * Sections and subsections * Field definitions * Dynamic content * Variable placeholders ### Default Values * Predefined fields * Standard responses * Common settings * Initial assignments ### Automation Rules * Automatic field population * Conditional logic * Required actions * Workflow triggers ## Best Practices ### Template Design * Clear organization * Consistent structure * Comprehensive coverage * User-friendly format ### Content Management * Regular updates * Version control * Change documentation * Usage tracking ### Team Usage * Training materials * Usage guidelines * Access controls * Feedback collection ### Quality Assurance * Regular reviews * Validation checks * Effectiveness monitoring * User feedback ## Using Templates ### In Case Management * Quick case creation * Standardized responses * Consistent documentation * Efficient handling ### In Task Management * Structured workflows * Clear procedures * Repeatable processes * Quality assurance ### In Reporting * Template usage metrics * Efficiency analysis * Process improvements * Success tracking ## Related Documentation * [Case Management](../../cases/introduction.mdx) * [Task Management](../../tasks/introduction.mdx) # Workflows Source: https://docs.casebender.com/en/settings/workflows/introduction Create and manage automated workflows to streamline your case management processes in CaseBender. ## Overview The Workflow Settings section allows you to create automated workflows that execute actions based on specific triggers in your CaseBender instance. This guide will walk you through the process of setting up and configuring workflows. Workflow Dashboard Light Workflow Dashboard Dark ## Creating a New Workflow ### Step 1: Basic Configuration Start by clicking the "Create" button and filling out the basic workflow information: Create Workflow Form Light Create Workflow Form Dark ### Step 2: Workflow Details Configure the detailed settings for your workflow: Workflow Details Form Light Workflow Details Form Dark Fill out the required information such as: * Workflow name * Description * Priority level * Execution settings ### Step 3: Organization Settings Specify which organizations can access and use this workflow: Organization Settings Light Organization Settings Dark * Select applicable organizations * Configure organization-specific settings * Set access permissions ## Configuring Workflow Logic ### Step 1: Select Trigger Choose the event that will initiate your workflow: Select Trigger Light Select Trigger Dark Available triggers may include: * Case creation or updates * Task assignments * Status changes * Custom events ### Step 2: Add Actions Click the plus button on flow edges to add actions to your workflow: Add Action Modal Light Add Action Modal Dark ### Step 3: Configure Action Select and configure each action in your workflow: Action Configuration Light Action Configuration Dark ### Step 4: Action Details Provide detailed configuration for each action: Action Details Light Action Details Dark Configure settings such as: * Action type specific parameters * Conditional logic * Input/output mapping * Error handling ### Step 5: Review Workflow Review your complete workflow with all configured actions: Complete Workflow Light Complete Workflow Dark ## Best Practices ### Workflow Design * Keep workflows focused and specific * Use clear, descriptive names * Document the purpose and expected outcomes * Test workflows thoroughly before activation ### Performance Considerations * Optimize action sequences * Consider execution time and resources * Monitor workflow performance * Handle errors appropriately ### Maintenance * Regularly review and update workflows * Monitor execution logs * Keep documentation current * Validate triggers and actions periodically # Task Analytics Source: https://docs.casebender.com/en/tasks/analytics This guide covers the analytics and reporting features available for monitoring and improving task management efficiency. ## Overview Task analytics provide insights into: * Team performance * Task efficiency * Resource utilization * Process bottlenecks * Quality metrics !\[Analytics Dashboard] *Screenshot showing the main analytics dashboard* ## Key Metrics ### 1. Time-Based Metrics Track time-related performance: * Average completion time * Time in each status * Response time * Overdue tasks * Time estimates vs. actuals ### 2. Volume Metrics Monitor task quantities: * Total tasks * Tasks by status * Tasks by priority * Tasks by type * Tasks by assignee ### 3. Quality Metrics Assess task quality: * Completion rate * Rework rate * Review outcomes * Error rates * Customer satisfaction ### 4. Team Metrics Evaluate team performance: * Individual workload * Team capacity * Assignment balance * Collaboration level * Response times ## Dashboard Views ### 1. Executive Dashboard High-level overview: * Key performance indicators * Trend analysis * Strategic metrics * Resource allocation * Risk indicators !\[Executive Dashboard] *Screenshot showing executive-level metrics and KPIs* ### 2. Team Dashboard Team-focused metrics: * Team performance * Workload distribution * Collaboration patterns * Efficiency metrics * Quality indicators !\[Team Dashboard] *Screenshot showing team-level analytics* ### 3. Personal Dashboard Individual metrics: * Task progress * Time tracking * Due dates * Priority queue * Performance trends !\[Personal Dashboard] *Screenshot showing individual performance metrics* ## Reports ### Standard Reports Pre-configured reports: 1. **Task Summary Report** * Overall statistics * Status distribution * Priority breakdown * Time analysis 2. **Team Performance Report** * Individual metrics * Team comparisons * Workload analysis * Efficiency scores 3. **Quality Report** * Completion rates * Review outcomes * Error analysis * Customer feedback 4. **Time Analysis Report** * Duration metrics * Delay analysis * Response times * Estimation accuracy ### Custom Reports Build custom reports with: * Selected metrics * Custom filters * Specific timeframes * Chosen formats * Automated delivery !\[Custom Reports] *Screenshot showing custom report builder* ## Analytics Features ### 1. Trend Analysis Track changes over time: * Historical comparisons * Pattern recognition * Seasonal variations * Growth indicators * Prediction models ### 2. Bottleneck Detection Identify process issues: * Status bottlenecks * Resource constraints * Delay patterns * Process gaps * Improvement areas ### 3. Resource Analysis Monitor resource usage: * Team utilization * Skill distribution * Capacity planning * Workload balance * Resource gaps ### 4. Performance Forecasting Predict future trends: * Completion estimates * Resource needs * Capacity requirements * Risk assessment * Growth planning ## Visualization Options ### Charts and Graphs Various visualization types: * Line charts * Bar graphs * Pie charts * Heat maps * Scatter plots * Gantt charts ### Interactive Features Dynamic analysis tools: * Drill-down capability * Custom filters * Real-time updates * Export options * Sharing features !\[Visualization Tools] *Screenshot showing various chart types and interactive features* ## Best Practices ### 1. Metric Selection Choose metrics that: * Align with goals * Provide actionable insights * Are measurable * Drive improvement * Support decisions ### 2. Data Quality Ensure data accuracy: * Regular validation * Clean data * Consistent tracking * Complete information * Timely updates ### 3. Report Design Create effective reports: * Clear layout * Relevant metrics * Visual clarity * Actionable insights * Regular updates ### 4. Analysis Process Follow structured analysis: * Define objectives * Gather data * Analyze patterns * Draw conclusions * Make recommendations ## Integration Options ### Data Sources Connect with: * Task database * Time tracking * Project management * External systems * Custom sources ### Export Options Export data to: * Excel * PDF * CSV * API endpoints * Custom formats ## Security and Privacy ### Data Protection Secure analytics data: * Access controls * Data encryption * Audit logging * Privacy compliance * Data retention ### User Permissions Control access to: * Metrics visibility * Report access * Export rights * Analysis tools * Custom reports For more information about task settings, see [Task Settings](./settings.mdx). # Creating Tasks Source: https://docs.casebender.com/en/tasks/creating-tasks This guide explains the different methods and options available for creating tasks in the system. ## Methods of Creation ### 1. Manual Creation Tasks can be created manually through several interfaces: * Using the "New Task" button in the task list * From within a case detail view * Through the quick actions menu * Via the task templates interface !\[Create Task Dialog] *Screenshot showing the task creation dialog with all available fields* ### 2. From Templates Task templates provide standardized formats for common tasks: * Select from predefined templates * Use organization-specific templates * Customize template fields * Save new templates for reuse !\[Task Templates] *Screenshot showing the template selection interface* ### 3. From Cases Create tasks directly within cases: * Add investigation tasks * Create follow-up actions * Set up review tasks * Generate documentation tasks ## Required Fields When creating a task, these fields are mandatory: * **Title**: Clear description of the task * **Priority**: Importance level * **Due Date**: Completion deadline * **Status**: Initial task state * **Type**: Task category ## Optional Fields Additional fields available during task creation: * **Description**: Detailed task information * **Assignee**: Responsible team member * **Parent Case**: Associated case * **Dependencies**: Related tasks * **Attachments**: Relevant files * **Custom Fields**: Organization-specific data ## Task Creation Settings Administrators can configure task creation options: * Default values * Required fields * Available templates * Custom fields * Automation rules !\[Task Settings] *Screenshot showing the administrative settings for task creation* ## Task Types Common task types include: 1. **Investigation Tasks** * Evidence collection * Analysis work * Incident response 2. **Documentation Tasks** * Report writing * Evidence documentation * Procedure updates 3. **Review Tasks** * Quality assurance * Peer review * Management approval 4. **Operational Tasks** * System updates * Configuration changes * Maintenance work ## Priority Levels Tasks can be assigned different priority levels: * **Critical**: Immediate attention required * **High**: Urgent but not critical * **Medium**: Normal priority * **Low**: Can be addressed later ## Best Practices ### 1. Task Naming * Use clear, action-oriented titles * Include key information in the title * Follow naming conventions ### 2. Task Planning * Set realistic deadlines * Consider dependencies * Align with team capacity ### 3. Task Assignment * Match skills to requirements * Consider workload balance * Include necessary context ### 4. Task Organization * Use appropriate templates * Add relevant tags * Link related items ## Automation Options Tasks can be created automatically through: * Case triggers * Scheduled events * Integration webhooks * Custom workflows ## Task Dependencies When creating dependent tasks: 1. Identify prerequisites 2. Set logical order 3. Define relationships 4. Configure notifications ## Next Steps After creating a task: 1. Add detailed description 2. Attach relevant files 3. Set up notifications 4. Brief assigned members 5. Monitor progress ## Integration Features Tasks integrate with: * Case management * Team calendars * Email notifications * External systems For more information on managing tasks, see [Working with Tasks](./working-with-tasks.mdx). # Task Management Source: https://docs.casebender.com/en/tasks/introduction The Task Management system provides a structured way to create, track, and manage action items within cases and investigations. ## Overview Tasks are actionable items that need to be completed as part of case investigations or general security operations. Each task represents a specific action, assignment, or milestone that contributes to resolving a case or addressing a security concern. !\[Task List View] *Screenshot showing the main task list view with filters, priorities, and assignments* ## Key Features * **Task Lifecycle Management**: Track tasks from creation to completion * **Priority Levels**: Assign and manage task priorities * **Due Date Tracking**: Set and monitor task deadlines * **Team Assignment**: Delegate tasks to team members * **Progress Tracking**: Monitor task completion status * **Task Dependencies**: Create and manage task relationships * **Attachment Support**: Add relevant files and documentation * **Integration with Cases**: Link tasks to specific cases ## Task Properties ### Core Properties * **Task ID**: Unique identifier (auto-generated) * **Title**: Clear description of the task * **Description**: Detailed information about the task * **Status**: Current state (Open, In Progress, Completed, etc.) * **Priority**: Importance level (Low, Medium, High, Critical) * **Due Date**: Deadline for task completion * **Type**: Category of task (Investigation, Analysis, Documentation, etc.) ### Metadata * **Created By**: User who created the task * **Created At**: Timestamp of task creation * **Updated At**: Last modification timestamp * **Assigned To**: Team member responsible for the task * **Parent Case**: Associated case (if applicable) * **Completion**: Progress percentage or completion status ## Task Organization Tasks can be organized in multiple ways: * **By Case**: Tasks associated with specific cases * **By Priority**: Grouped by importance level * **By Status**: Organized by current state * **By Assignee**: Grouped by team member * **By Due Date**: Chronological organization * **Custom Views**: User-defined organization methods ## Related Components Tasks are integrated with several other components: * **Cases**: Parent cases that tasks belong to * **Comments**: Discussion threads on tasks * **Attachments**: Related files and documents * **Notifications**: Alerts about task updates * **Timeline**: Activity history of tasks * **Reports**: Task status and progress reports !\[Task Detail View] *Screenshot showing the detailed view of a task with all its components* ## Task Workflows Tasks follow defined workflows: 1. **Creation**: Initial task setup 2. **Assignment**: Task delegation 3. **Progress Updates**: Status changes 4. **Review**: Quality checks 5. **Completion**: Task closure ## Best Practices 1. **Clear Descriptions**: Write specific, actionable task descriptions 2. **Realistic Deadlines**: Set achievable due dates 3. **Priority Management**: Assign appropriate priority levels 4. **Regular Updates**: Keep task status current 5. **Documentation**: Maintain clear task notes and attachments ## Next Sections * [Creating Tasks](./creating-tasks.mdx) * [Task Workflows](./workflows.mdx) * [Working with Tasks](./working-with-tasks.mdx) * [Task Settings](./settings.mdx) * [Task Analytics](./analytics.mdx) # Task Settings Source: https://docs.casebender.com/en/tasks/settings This guide covers the configuration options and settings available for customizing the task management system. ## Access Settings Navigate to Settings > Tasks to configure task-related options: !\[Task Settings Page] *Screenshot showing the main task settings interface* ## Status Configuration ### Managing Task Statuses Configure available task statuses: 1. **Create Status**: * Label and description * Color coding * Stage assignment * Order in workflow 2. **Edit Status**: * Update properties * Modify transitions * Change automation * Adjust permissions 3. **Delete Status**: * Remove unused statuses * Handle existing tasks * Update workflows !\[Status Management] *Screenshot of the status management interface* ## Templates ### Task Templates Create and manage templates: * Standard templates * Team templates * Project templates * Custom templates ### Template Properties Configure template settings: * Default fields * Required fields * Automation rules * Team assignments * Dependencies !\[Template Configuration] *Screenshot showing template creation and editing* ## Field Configuration ### Custom Fields Add organization-specific fields: * Text fields * Number fields * Date fields * Selection fields * User fields * Custom types ### Field Properties Configure field settings: * Field type * Default value * Validation rules * Required status * Visibility rules !\[Custom Fields] *Screenshot of custom field configuration* ## Automation Settings ### Workflow Rules Configure automated actions: 1. **Triggers**: * Status changes * Priority updates * Due date changes * Assignment changes * Custom events 2. **Actions**: * Update fields * Send notifications * Create tasks * Update related items * External integrations !\[Workflow Automation] *Screenshot of workflow automation settings* ## Team Settings ### Access Control Configure team permissions: * View permissions * Edit permissions * Delete permissions * Assignment rules * Template access ### Team Organization Set up team structure: * Team hierarchy * User groups * Role definitions * Access levels * Collaboration rules !\[Team Configuration] *Screenshot showing team and permission settings* ## Integration Settings ### External Systems Configure integrations with: * Project management tools * Communication platforms * Calendar systems * Document storage * Custom applications ### API Configuration Manage API settings: * Authentication * Rate limits * Webhooks * Custom endpoints * Data mapping !\[Integration Settings] *Screenshot of integration configuration* ## Notification Settings ### Email Notifications Configure email alerts for: * Task creation * Status changes * Comments * Due dates * Assignments * Mentions ### System Notifications Set up in-app notifications: * Priority levels * Delivery methods * Frequency rules * Custom triggers * Team alerts !\[Notification Configuration] *Screenshot showing notification settings* ## View Settings ### List View Configure list display: * Column selection * Default sorting * Grouping options * Filter presets * Custom views ### Board View Configure Kanban boards: * Column layout * Card design * Swimlanes * WIP limits * Visual indicators ### Calendar View Configure calendar display: * Time scale * Default view * Color coding * Event display * Resource view !\[View Configuration] *Screenshot showing view customization options* ## Analytics Settings ### Metrics Configure tracking for: * Completion rates * Time tracking * Team performance * Quality metrics * Custom KPIs ### Reports Set up reporting: * Standard reports * Custom reports * Dashboards * Export options * Scheduling !\[Analytics Settings] *Screenshot of analytics and reporting configuration* ## Best Practices ### 1. Status Configuration * Use clear names * Logical workflow * Consistent colors * Clear transitions * Regular review ### 2. Template Management * Standardize common tasks * Regular updates * Team feedback * Clear documentation * Version control ### 3. Field Organization * Logical grouping * Clear labels * Helpful hints * Validation rules * Regular cleanup ### 4. Automation Rules * Start simple * Test thoroughly * Document rules * Monitor performance * Regular review ### 5. Security * Role-based access * Regular audits * Secure integrations * Data protection * Compliance checks For information about working with tasks, see [Working with Tasks](./working-with-tasks.mdx). # Task Workflows Source: https://docs.casebender.com/en/tasks/workflows This guide explains how tasks progress through different stages and how to manage task workflows effectively. ## Task Status Stages Tasks move through several standard stages: 1. **Open**: Newly created tasks awaiting action 2. **In Progress**: Tasks currently being worked on 3. **Under Review**: Tasks pending verification 4. **Completed**: Successfully finished tasks 5. **Blocked**: Tasks that cannot proceed 6. **Cancelled**: Terminated or obsolete tasks !\[Task Status Flow] *Diagram showing the progression of tasks through different status stages* ## Status Management ### Status Properties Each status has specific properties: * **Label**: Display name * **Description**: Status meaning * **Color**: Visual indicator * **Stage**: Workflow phase * **Automation Rules**: Associated actions ### Status Transitions Valid status changes include: * Open → In Progress * In Progress → Under Review * Under Review → Completed * Any Status → Blocked * Any Status → Cancelled !\[Status Transitions] *Diagram showing valid status transitions and conditions* ## Task Priorities ### Priority Levels Tasks can be prioritized as: 1. **Critical** * Immediate action required * High business impact * Time-sensitive issues 2. **High** * Urgent but not critical * Significant impact * Near-term deadlines 3. **Medium** * Standard priority * Moderate impact * Flexible timeline 4. **Low** * Non-urgent * Minimal impact * Background tasks ### Priority Management Effective priority handling: * Regular priority reviews * Escalation procedures * Impact assessment * Resource allocation ## Workflow Automation ### Automated Actions Configure actions for: * Status changes * Priority updates * Assignment changes * Deadline modifications * Notification triggers ### Trigger Events Automation can be triggered by: * Time-based events * Status changes * User actions * External events * Related task updates !\[Workflow Automation] *Screenshot showing workflow automation configuration* ## Task Dependencies ### Types of Dependencies 1. **Finish to Start** * Task B can't start until Task A finishes * Most common dependency type 2. **Start to Start** * Tasks must start together * Parallel activities 3. **Finish to Finish** * Tasks must finish together * Coordinated completion 4. **Start to Finish** * Rare, specialized dependency * Complex relationships ### Managing Dependencies Best practices include: * Clear documentation * Visual representation * Impact analysis * Change management ## Progress Tracking ### Completion Metrics Monitor task progress through: * Percentage complete * Milestone achievement * Time tracking * Quality metrics ### Progress Updates Regular updates should include: * Status changes * Work completed * Blockers identified * Next steps planned ## Team Collaboration ### Assignment Rules Task assignment considers: * Team member skills * Current workload * Availability * Domain expertise ### Handoff Procedures When transferring tasks: 1. Document current status 2. Brief new assignee 3. Transfer resources 4. Update stakeholders ## Reporting and Analytics ### Workflow Metrics Track key indicators: * Cycle time * Lead time * Resolution time * Blockers * Efficiency ### Performance Analysis Analyze workflow health: * Bottleneck identification * Resource utilization * Quality metrics * Team performance !\[Workflow Analytics] *Screenshot showing workflow analytics dashboard* ## Best Practices ### 1. Status Management * Use clear status definitions * Regular status updates * Proper documentation * Timely transitions ### 2. Priority Handling * Regular priority reviews * Clear escalation paths * Resource alignment * Impact assessment ### 3. Workflow Efficiency * Minimize bottlenecks * Automate routine tasks * Clear communication * Regular reviews ### 4. Team Coordination * Clear responsibilities * Effective handoffs * Regular updates * Team visibility ## Configuration ### Setting Up Workflows 1. Define status stages 2. Configure transitions 3. Set up automation 4. Test workflows 5. Train team members ### Customization Options Adapt workflows for: * Team preferences * Project requirements * Organization needs * Compliance rules For more information on working with tasks, see [Working with Tasks](./working-with-tasks.mdx). # Working with Tasks Source: https://docs.casebender.com/en/tasks/working-with-tasks This guide covers the day-to-day operations and features available when working with tasks in the system. ## Task Interface The task interface provides comprehensive task management: !\[Task Interface] *Screenshot showing the main task interface with all components* ### Key Areas 1. **Header**: Task title and quick actions 2. **Details Panel**: Core task properties 3. **Activity Feed**: Recent updates 4. **Related Items**: Linked content ## Task Views ### 1. List View The main task list provides: * Task overview * Quick filters * Bulk actions * Sort options * Custom views !\[Task List] *Screenshot showing the task list view with various options* ### 2. Board View Kanban-style task management: * Status columns * Drag-and-drop * Visual indicators * Quick updates * Team visibility !\[Task Board] *Screenshot showing the Kanban board view* ### 3. Calendar View Time-based task visualization: * Due date tracking * Schedule management * Timeline view * Resource planning * Milestone tracking !\[Task Calendar] *Screenshot showing the calendar view* ## Task Actions ### Basic Operations Common task actions include: * Edit task details * Update status * Change priority * Modify due date * Add comments * Attach files ### Advanced Operations Additional task capabilities: * Create subtasks * Set dependencies * Clone tasks * Export data * Generate reports ## Task Components ### 1. Comments Facilitate team discussion: * Add updates * Ask questions * Share information * Mention team members * Attach files ### 2. Attachments Manage task-related files: * Upload documents * Add screenshots * Link resources * Version control * Preview files ### 3. Subtasks Break down complex tasks: * Create checklist items * Track progress * Assign ownership * Set priorities * Monitor completion ### 4. Time Tracking Monitor task effort: * Log work hours * Track estimates * Record actuals * View timesheets * Analyze efficiency ## Task Organization ### Filtering Filter tasks by: * Status * Priority * Assignee * Due date * Tags * Custom fields ### Sorting Arrange tasks by: * Priority * Due date * Creation date * Status * Assignee * Custom order ### Grouping Group tasks by: * Status * Assignee * Priority * Project * Custom fields * Timeline ## Task Communication ### Notifications Receive updates about: * Status changes * Comments * Assignments * Due dates * Mentions * Attachments ### Integration Connect with: * Email * Slack * Teams * Calendar * Mobile apps ## Task Analysis ### Progress Tracking Monitor task progress: * Completion percentage * Time tracking * Milestone status * Dependency status * Quality metrics ### Performance Metrics Analyze task efficiency: * Cycle time * Lead time * Resolution time * Work distribution * Team velocity ## Mobile Access ### Mobile Features Access tasks on mobile: * View task details * Update status * Add comments * Upload photos * Receive notifications !\[Mobile Interface] *Screenshot showing the mobile task interface* ## Best Practices ### 1. Task Management * Keep tasks updated * Use clear titles * Set realistic deadlines * Track progress regularly * Document decisions ### 2. Team Collaboration * Communicate clearly * Update promptly * Share context * Follow up regularly * Maintain visibility ### 3. Time Management * Prioritize effectively * Track time accurately * Manage deadlines * Balance workload * Plan realistically ### 4. Documentation * Write clear descriptions * Attach relevant files * Record decisions * Update status * Maintain history ## Keyboard Shortcuts Common task shortcuts: * `Ctrl/Cmd + N`: New task * `Ctrl/Cmd + E`: Edit task * `Ctrl/Cmd + D`: Duplicate task * `Space`: Quick update * `Esc`: Cancel/Close ## Tips and Tricks ### Productivity Tips 1. Use templates for recurring tasks 2. Set up custom views 3. Use bulk actions 4. Configure notifications 5. Utilize keyboard shortcuts ### Organization Tips 1. Use consistent naming 2. Apply relevant tags 3. Group related tasks 4. Maintain clean lists 5. Archive completed tasks For information about task workflows and status management, see [Task Workflows](./workflows.mdx). # Create API Key Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/create POST /api-keys Create a new API key # Delete API Key Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/delete DELETE /api-keys/{id} Delete an API key # Get API Key by ID Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/get-by-id GET /api-keys/{id} Retrieve a specific API key # List API Keys Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/list GET /api-keys List all API keys for the current user or organization # Rotate API Key Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/rotate POST /api-keys/{id}/rotate Rotate an API key to generate new credentials # Get Available Scopes Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/scopes GET /api-keys/scopes Get list of available API scopes # Get API Key Usage Stats Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/stats GET /api-keys/{id}/stats Get usage statistics for an API key # Update API Key Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/update PUT /api-keys/{id} Update an existing API key # Get Alert Audit History Source: https://docs.casebender.com/en/api-reference/endpoint/audit/alert-history GET /audit/alert/{alertId} Get the complete audit history for a specific alert # Get Audit Record Source: https://docs.casebender.com/en/api-reference/endpoint/audit/get-by-id GET /audit/{id} Retrieve a specific audit record # List Audit Records Source: https://docs.casebender.com/en/api-reference/endpoint/audit/list GET /audit List audit records with optional filters # Get Audit Statuses Source: https://docs.casebender.com/en/api-reference/endpoint/audit/statuses GET /audit/statuses Get list of available audit statuses # Bulk Assign Alerts Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-assign POST /bulk/alerts/assign Bulk assign alerts to a user (FUNC-014) # Bulk Delete Alerts Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-delete DELETE /bulk/alerts Bulk delete multiple alerts (soft delete) (FUNC-014) # Bulk Update Alerts Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-update POST /bulk/alerts Bulk update multiple alerts (FUNC-014) # Bulk Assign Cases Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-assign POST /bulk/cases/assign Bulk assign cases to a user and/or teams (FUNC-014) # Bulk Delete Cases Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-delete DELETE /bulk/cases Bulk delete multiple cases (soft delete) (FUNC-014) # Bulk Change Case Status Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-status POST /bulk/cases/status Bulk change case status with mandatory task validation (FUNC-014, FUNC-031) # Bulk Update Case Tags Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-tags POST /bulk/cases/tags Bulk add/remove/set tags on cases (FUNC-014) # Bulk Set Case TLP Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-tlp POST /bulk/cases/tlp Bulk set TLP/PAP classification on cases with optional propagation (FUNC-014, FUNC-044) # Bulk Update Cases Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-update POST /bulk/cases Bulk update multiple cases (FUNC-014) # Delete Comment Source: https://docs.casebender.com/en/api-reference/endpoint/comments/delete DELETE /comments/{id} Delete a comment (soft delete) # Add Task Comment Source: https://docs.casebender.com/en/api-reference/endpoint/comments/task-comments-add POST /tasks/{taskId}/comments Add a new comment to a task. Supports hierarchical comment structure (FUNC-041). # Get Task Comments Source: https://docs.casebender.com/en/api-reference/endpoint/comments/task-comments-get GET /tasks/{taskId}/comments Get all comments for a specific task. Supports hierarchical comment structure (FUNC-041). # Update Comment Source: https://docs.casebender.com/en/api-reference/endpoint/comments/update PUT /comments/{id} Update an existing comment # Create Custom Field Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/create POST /custom-fields Create a new custom field definition (admin only) # Delete Custom Field Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/delete DELETE /custom-fields/{id} Delete a custom field definition (admin only) # Get Custom Field by ID Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/get-by-id GET /custom-fields/{id} Retrieve a specific custom field definition # List Custom Fields Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/list GET /custom-fields List all custom field definitions # Update Custom Field Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/update PUT /custom-fields/{id} Update an existing custom field definition (admin only) # Create Integration Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/create POST /integrations Create a new integration configuration (admin only) # Delete Integration Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/delete DELETE /integrations/{id} Delete an integration configuration (admin only) # Get Integration by ID Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/get-by-id GET /integrations/{id} Retrieve a specific integration configuration # List Integrations Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/list GET /integrations List all configured integrations # List Integration Types Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/types GET /integrations/types Get all available integration types # Update Integration Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/update PUT /integrations/{id} Update an existing integration configuration (admin only) # Get Alerts by Source Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/alerts-source GET /metrics/alerts/source Get alert count grouped by source # Get Cases by Severity Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/cases-severity GET /metrics/cases/severity Get case count grouped by severity level # Get Cases by Status Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/cases-status GET /metrics/cases/status Get case count grouped by status # Get Case Trend Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/cases-trend GET /metrics/cases/trend Get case creation trend over time # Get Dashboard Metrics Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/dashboard GET /metrics/dashboard Get overview metrics for the dashboard # Get MTTR Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/mttr GET /metrics/mttr Get Mean Time To Resolve for cases # Create Organization Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/create POST /organizations Create a new organization (admin only) # Delete Organization Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/delete DELETE /organizations/{id} Soft delete an organization (admin only) # Get Organization by ID Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/get-by-id GET /organizations/{id} Retrieve a specific organization by its ID # Get Organization Hierarchy Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/hierarchy GET /organizations/hierarchy Get the organization hierarchy tree # List Organizations Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/list GET /organizations List all organizations with optional filters # Update Organization Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/update PUT /organizations/{id} Update an existing organization (admin only) # Create Playbook Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/create POST /playbooks Create a new playbook # Delete Playbook Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/delete DELETE /playbooks/{id} Delete a playbook # Get Playbook Executions Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/executions GET /playbooks/{id}/executions Get execution history for a playbook # Get Playbook by ID Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/get-by-id GET /playbooks/{id} Retrieve a specific playbook by its ID # List Playbooks Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/list GET /playbooks List all playbooks with optional filters # Trigger Playbook Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/trigger POST /playbooks/{id}/trigger Manually trigger a playbook execution # Update Playbook Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/update PUT /playbooks/{id} Update an existing playbook # Get SLA Configuration Source: https://docs.casebender.com/en/api-reference/endpoint/sla/config GET /sla/config Get the global SLA configuration # Get SLA History Source: https://docs.casebender.com/en/api-reference/endpoint/sla/history GET /sla/history/{entityType}/{entityId} Get the SLA status history for a case or alert # Get SLA Status Source: https://docs.casebender.com/en/api-reference/endpoint/sla/status GET /sla/status/{entityType}/{entityId} Get the current SLA status for a case or alert # Get SLA Template Source: https://docs.casebender.com/en/api-reference/endpoint/sla/template-by-id GET /sla/templates/{id} Get a specific SLA template by ID # List SLA Templates Source: https://docs.casebender.com/en/api-reference/endpoint/sla/templates GET /sla/templates Get all SLA templates # Add User to Team Source: https://docs.casebender.com/en/api-reference/endpoint/teams/add-user POST /teams/{id}/users/{userId} Add a user to a team # Create Team Source: https://docs.casebender.com/en/api-reference/endpoint/teams/create POST /teams Create a new team (admin only) # Delete Team Source: https://docs.casebender.com/en/api-reference/endpoint/teams/delete DELETE /teams/{id} Delete a team (admin only) # Get Team by ID Source: https://docs.casebender.com/en/api-reference/endpoint/teams/get-by-id GET /teams/{id} Retrieve a specific team by its ID # List Teams Source: https://docs.casebender.com/en/api-reference/endpoint/teams/list GET /teams List all teams with optional filters # Remove User from Team Source: https://docs.casebender.com/en/api-reference/endpoint/teams/remove-user DELETE /teams/{id}/users/{userId} Remove a user from a team # Update Team Source: https://docs.casebender.com/en/api-reference/endpoint/teams/update PUT /teams/{id} Update an existing team (admin only) # Create Template Source: https://docs.casebender.com/en/api-reference/endpoint/templates/create POST /templates Create a new template # Delete Template Source: https://docs.casebender.com/en/api-reference/endpoint/templates/delete DELETE /templates/{id} Delete a template # Get Template by ID Source: https://docs.casebender.com/en/api-reference/endpoint/templates/get-by-id GET /templates/{id} Retrieve a specific template # List Templates Source: https://docs.casebender.com/en/api-reference/endpoint/templates/list GET /templates List all templates with optional entity type filter # Update Template Source: https://docs.casebender.com/en/api-reference/endpoint/templates/update PUT /templates/{id} Update an existing template # Get TLP Audit Logs Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/audit-logs GET /tlp/audit-logs Get TLP access and change audit logs # List TLP Change Requests Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/change-requests GET /tlp/change-requests List pending TLP change requests awaiting approval # Check TLP Access Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/check-access POST /tlp/check-access Check if the current user has TLP clearance to access an entity # Get TLP Constants Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/constants GET /tlp/constants Get TLP level constants including labels, descriptions, and colors for UI rendering # Get Entity TLP Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/entity-get GET /tlp/entity/{type}/{id} Get the TLP level for a specific entity (case, alert, task, etc.) # Change Entity TLP Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/entity-update PUT /tlp/entity/{type}/{id} Change the TLP level for an entity. May require approval for high TLP levels. # Process TLP Change Request Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/process-change-request POST /tlp/change-requests/{id}/process Approve or reject a pending TLP change request # Propagate TLP Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/propagate POST /tlp/propagate Propagate TLP from a parent entity to its children # Get User Max TLP Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/user-max GET /tlp/user/max Get the maximum TLP level the current user can access # Get User by ID Source: https://docs.casebender.com/en/api-reference/endpoint/users/get-by-id GET /users/{id} Retrieve a specific user # List Users Source: https://docs.casebender.com/en/api-reference/endpoint/users/list GET /users List all users with optional filters # Get Current User Source: https://docs.casebender.com/en/api-reference/endpoint/users/me GET /users/me Get the currently authenticated user # Update User Source: https://docs.casebender.com/en/api-reference/endpoint/users/update PUT /users/{id} Update an existing user (admin only) # Create Webhook Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/create POST /webhooks Create a new webhook subscription # Delete Webhook Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/delete DELETE /webhooks/{id} Delete a webhook subscription # Get Delivery Logs Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/deliveries GET /webhooks/{id}/deliveries Get delivery history for a webhook # List Event Types Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/event-types GET /webhooks/event-types Get all available webhook event types # Get Webhook by ID Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/get-by-id GET /webhooks/{id} Retrieve a specific webhook subscription # List Webhooks Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/list GET /webhooks List all webhook subscriptions # Test Webhook Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/test POST /webhooks/{id}/test Send a test payload to a webhook # Update Webhook Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/update PUT /webhooks/{id} Update an existing webhook subscription # Create Workflow Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/create POST /workflows Create a new workflow # Delete Workflow Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/delete DELETE /workflows/{id} Delete a workflow # Execute Workflow Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/execute POST /workflows/{id}/execute Execute a workflow manually with provided context # Get Workflow Executions Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/executions GET /workflows/{id}/executions Get execution history for a workflow # Get Workflow by ID Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/get-by-id GET /workflows/{id} Retrieve a specific workflow # List Workflows Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/list GET /workflows List all workflows with optional filters # Update Workflow Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/update PUT /workflows/{id} Update an existing workflow # Bulk Merge Alerts Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-merge POST /bulk/alerts/merge Bulk merge alerts into a target case (FUNC-014) # Bulk Change Alert Status Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-status POST /bulk/alerts/status Bulk change alert status (FUNC-014) # Bulk Delete Observables Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/observables-delete DELETE /bulk/observables Bulk delete multiple observables (FUNC-014) # Bulk Set Observable IOC Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/observables-ioc POST /bulk/observables/ioc Bulk set IOC flag on observables (FUNC-014) # Bulk Update Observables Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/observables-update POST /bulk/observables Bulk update multiple observables (FUNC-014) # Bulk Assign Tasks Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-assign POST /bulk/tasks/assign Bulk assign tasks to a user and/or teams (FUNC-014, FUNC-045) # Bulk Delete Tasks Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-delete DELETE /bulk/tasks Bulk delete multiple tasks (soft delete) (FUNC-014) # Bulk Set Task Mandatory Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-mandatory POST /bulk/tasks/mandatory Bulk set mandatory flag on tasks (FUNC-014, FUNC-031) # Bulk Update Tasks Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-update POST /bulk/tasks Bulk update multiple tasks (FUNC-014)