# AI Insights
Source: https://docs.casebender.com/en/alerts/ai-insights
Leverage AI-powered analysis for alert investigation
## Overview
The AI Insights tab provides automated analysis and recommendations powered by artificial intelligence. This feature helps analysts quickly understand alert context, identify patterns, and make informed decisions about alert handling.
## Analysis Categories
### Threat Assessment
* Risk scoring
* Severity recommendations
* Impact analysis
* Confidence rating
### Pattern Recognition
* Similar past alerts
* Known attack patterns
* Anomaly detection
* Behavioral analysis
### Context Enhancement
* Related external threats
* Industry context
* Historical perspective
* Environmental factors
## AI Capabilities
### Natural Language Processing
* Description analysis
* Context extraction
* Entity recognition
* Relationship mapping
### Machine Learning Models
* Pattern detection
* Anomaly identification
* Risk prediction
* Similarity scoring
### Automated Enrichment
* Threat intelligence correlation
* OSINT integration
* Historical data analysis
* Environmental context
## Insights Display
### Summary View
* Key findings
* Risk assessment
* Recommended actions
* Critical observations
### Detailed Analysis
* In-depth explanations
* Supporting evidence
* Confidence levels
* Alternative interpretations
### Recommendations
* Next steps
* Investigation paths
* Mitigation strategies
* Resource allocation
## Interactive Features
### Insight Exploration
1. Expand detailed analysis
2. View supporting evidence
3. Access related data
4. Track insight history
### Feedback Loop
* Mark insights helpful/unhelpful
* Add analyst notes
* Provide context
* Report inaccuracies
### Custom Analysis
* Request specific analysis
* Focus on particular aspects
* Adjust analysis parameters
* Save analysis preferences
## Best Practices
1. **Analysis Review**
* Validate AI findings
* Cross-reference data
* Document disagreements
* Track accuracy
2. **Investigation Flow**
* Start with summary
* Explore key findings
* Validate conclusions
* Document decisions
3. **Feedback Quality**
* Provide specific feedback
* Note false positives
* Suggest improvements
* Share context
## Model Training
### Data Sources
* Historical alerts
* Analyst feedback
* External threats
* Industry data
### Training Process
* Continuous learning
* Feedback incorporation
* Model updates
* Performance monitoring
## Next Steps
Configure automated responses
Explore alert analytics
# Alert Detail View
Source: https://docs.casebender.com/en/alerts/detail-view
Comprehensive view of individual alert information
## Overview
The Alert Detail View provides a comprehensive interface for viewing and managing individual alerts. It features a rich text editor for descriptions, file attachments, and multiple tabs for different aspects of the alert.
## Layout Structure
### Main Content Area
1. **Header Section**
* Back to list navigation
* Severity badge
* Editable title
* Action buttons
2. **Description Section**
* Rich text editor
* Support for formatting
* File attachment integration
* Image embedding
3. **Attachments Section**
* Image gallery with lightbox
* File list with previews
* Drag-and-drop upload
* Attachment management
### Right Sidebar
1. **Action Panel**
* Status updates
* Team assignments
* Tag management
* Custom field updates
* Case creation/linking
2. **Details Section**
* Creation information
* Last update timestamp
* Source details
* Reference information
### Activity Timeline
* Chronological activity log
* Status changes
* Assignment updates
* Comment additions
* Attachment uploads
## Tab Navigation
### Observables Tab
[Learn more about Observables](/en/alerts/observables)
* List of associated indicators
* Observable management
* Type categorization
* Enrichment status
### TTPs Tab
[Learn more about TTPs](/en/alerts/ttps)
* MITRE ATT\&CK mapping
* Technique details
* Procedure documentation
* Tactic categorization
### Similar Alerts Tab
[Learn more about Similar Alerts](/en/alerts/similar-alerts)
* Related alert discovery
* Similarity scoring
* Merge capabilities
* Pattern identification
### AI Insights Tab
[Learn more about AI Insights](/en/alerts/ai-insights)
* Automated analysis
* Risk assessment
* Recommended actions
* Pattern recognition
## Editing Capabilities
### Title Editing
* Direct inline editing
* Auto-save functionality
* Character limits
* Validation rules
### Description Management
* Rich text formatting
* Image embedding
* Link integration
* Version tracking
### File Attachments
* Multiple file upload
* Image preview
* File type support
* Size limitations
## Collaboration Features
### Comments and Notes
* Rich text comments
* @mentions support
* Reply threading
* Notification integration
### Team Assignment
* Single/multiple assignees
* Team visibility settings
* Assignment history
* Auto-assignment rules
## Best Practices
1. **Content Organization**
* Use clear titles
* Structure descriptions well
* Categorize attachments
* Tag appropriately
2. **Collaboration**
* Update status regularly
* Document key findings
* Use @mentions effectively
* Keep activity log clear
3. **Investigation**
* Review all tabs
* Document observations
* Link related items
* Update findings regularly
## Next Steps
Learn about observable management
Explore tactics and procedures
Understand alert correlation
Leverage AI analysis
# Alert List View
Source: https://docs.casebender.com/en/alerts/list-view
Navigate and manage multiple alerts efficiently
## Overview
The Alert List View provides a comprehensive interface for managing multiple alerts. It offers powerful filtering, bulk operations, and quick access to alert details.
## List Features
### Toolbar Actions
* **Multiple Selection**: Toggle checkbox to select multiple alerts
* **Refresh**: Update the alert list in real-time
* **Bulk Operations**:
* Create Case from selected alerts
* Merge alerts into existing case
* Bulk update alert properties
* Delete selected alerts
### Filtering and Search
* Search by alert title and description
* Filter by:
* Status
* Severity
* Assignee
* Reset filters to default view
### Selection Modes
1. **Individual Selection**
* Select alerts one by one
* Perform actions on specific alerts
2. **Bulk Selection**
* Select all visible alerts
* Select all matching alerts (across pages)
* Clear selection
## List Display
### Alert List Items
Each alert in the list shows:
* Severity indicator
* Title
* Status
* Assignment information
* Creation timestamp
* Quick action buttons
### Virtual Scrolling
* Efficient handling of large alert lists
* Load more functionality
* Smooth scrolling performance
## Bulk Operations
### Create Case
Convert multiple alerts into a new case:
1. Select relevant alerts
2. Click create case button
3. Fill case details
4. Confirm creation
### Merge with Case
Add alerts to an existing case:
1. Select alerts to merge
2. Click merge button
3. Search for target case
4. Confirm merge operation
### Bulk Update
Update multiple alerts simultaneously:
1. Select alerts to update
2. Click bulk update button
3. Choose fields to update
4. Apply changes
### Bulk Delete
Remove multiple alerts:
1. Select alerts to delete
2. Click delete button
3. Confirm deletion
## Empty States
### No Alerts
Displayed when no alerts exist:
* Informative message
* Guidance on creating alerts
### No Search Results
Shown when filters return no results:
* Suggestion to adjust filters
* Option to reset search
## Best Practices
1. **Selection Management**
* Use bulk selection for similar alerts
* Verify selection before bulk actions
* Clear selection after operations
2. **Filtering Strategy**
* Start with broad filters
* Refine based on results
* Use search for specific alerts
3. **Bulk Operations**
* Review selected items carefully
* Use preview when available
* Confirm irreversible actions
## Next Steps
Learn about detailed alert information
Master bulk alert management
# Alert Observables
Source: https://docs.casebender.com/en/alerts/observables
Manage indicators and observables associated with alerts
## Overview
The Observables tab allows you to track and manage various types of indicators associated with an alert. These observables can include IP addresses, domains, file hashes, and other relevant technical artifacts.
## Observable Types
### Network Indicators
* IP Addresses
* Domain Names
* URLs
* Email Addresses
* Network Services
### File Indicators
* File Hashes (MD5, SHA1, SHA256)
* File Names
* File Paths
* File Types
### System Indicators
* Registry Keys
* Process Names
* System Commands
* User Accounts
### Custom Indicators
* Custom Observable Types
* Organization-specific Indicators
* Industry-specific Artifacts
## Managing Observables
### Adding Observables
1. Click "Add Observable" button
2. Select observable type
3. Enter observable value
4. Add optional description
5. Set TLP/PAP levels if applicable
### Bulk Operations
* Import multiple observables
* Export observable list
* Bulk update TLP/PAP
* Bulk delete observables
### Observable Properties
* Type classification
* Value
* Description
* TLP (Traffic Light Protocol) level
* PAP (Permissible Actions Protocol) level
* First/Last seen timestamps
* Source information
## Observable Enrichment
### Automatic Enrichment
* Reputation data
* Geolocation information
* WHOIS data
* Historical context
* Related indicators
### Manual Analysis
* Add analysis notes
* Link to external sources
* Document investigation findings
* Tag related observables
## Visualization
### List View
* Sortable columns
* Quick filters
* Type indicators
* Enrichment status
### Relationship View
* Observable connections
* Related alerts
* Common patterns
* Timeline visualization
## Best Practices
1. **Data Quality**
* Validate observable format
* Remove false positives
* Document context
* Maintain consistent format
2. **Enrichment**
* Review enrichment data
* Update stale information
* Document findings
* Link related data
3. **Organization**
* Use consistent naming
* Group related observables
* Tag effectively
* Document relationships
## Next Steps
Explore tactics and procedures
Find related alerts
# Similar Alerts
Source: https://docs.casebender.com/en/alerts/similar-alerts
Discover and analyze related alerts
## Overview
The Similar Alerts tab helps identify and analyze alerts that may be related to the current alert. This feature uses various correlation methods to find potential connections and patterns across your alert data.
## Correlation Methods
### Content-based Similarity
* Title matching
* Description analysis
* Observable overlap
* TTP correlation
### Temporal Analysis
* Time-based clustering
* Frequency patterns
* Sequence detection
* Campaign timeline
### Contextual Correlation
* Source alignment
* Target comparison
* Attack pattern matching
* Team/Organization context
## Similarity Scoring
### Score Components
* Observable match percentage
* TTP overlap
* Temporal proximity
* Source correlation
* Target alignment
### Score Interpretation
* High confidence matches
* Potential relationships
* Weak correlations
* False positives
## Alert Management
### Viewing Similar Alerts
1. Sort by similarity score
2. Filter by time range
3. Group by correlation type
4. Focus on specific attributes
### Bulk Operations
* Select multiple alerts
* Create case from group
* Merge alerts
* Update status
### Alert Comparison
* Side-by-side view
* Difference highlighting
* Common attributes
* Unique characteristics
## Pattern Analysis
### Campaign Detection
* Alert clustering
* Pattern identification
* Campaign timeline
* Attack progression
### Threat Actor Analysis
* Common TTPs
* Observable patterns
* Target profiles
* Attack methodologies
## Visualization
### Timeline View
* Chronological display
* Frequency analysis
* Pattern highlighting
* Campaign mapping
### Relationship Graph
* Alert connections
* Observable links
* TTP relationships
* Pattern visualization
## Best Practices
1. **Analysis Workflow**
* Review highest scores first
* Validate relationships
* Document findings
* Update correlation rules
2. **Pattern Recognition**
* Look for campaigns
* Track progression
* Note anomalies
* Document insights
3. **Alert Management**
* Group related alerts
* Create cases appropriately
* Update statuses
* Document relationships
## Next Steps
Get AI-powered analysis
Configure correlation rules
# Alert TTPs
Source: https://docs.casebender.com/en/alerts/ttps
Track tactics, techniques, and procedures associated with alerts
## Overview
The TTPs (Tactics, Techniques, and Procedures) tab provides a comprehensive view of the MITRE ATT\&CK techniques and tactics associated with an alert, helping analysts understand and document adversary behavior.
## MITRE ATT\&CK Integration
### Framework Overview
* Enterprise ATT\&CK Matrix
* Mobile ATT\&CK Matrix
* ICS ATT\&CK Matrix
* Pre-ATT\&CK Tactics
### Mapping Capabilities
* Technique selection
* Sub-technique support
* Tactic categorization
* Confidence scoring
## Managing TTPs
### Adding Techniques
1. Browse or search ATT\&CK matrix
2. Select relevant technique
3. Choose sub-techniques if applicable
4. Set confidence level
5. Add supporting evidence
### Bulk Operations
* Import technique list
* Export TTP mapping
* Bulk update confidence
* Remove multiple techniques
### TTP Properties
* Technique ID
* Technique name
* Sub-technique details
* Confidence level
* Supporting evidence
* Detection status
* Mitigation status
## Documentation
### Evidence Collection
* Observable links
* Screenshot attachments
* Log excerpts
* Analysis notes
### Procedure Details
* Implementation specifics
* Tool usage
* Command syntax
* Execution timeline
## Analysis Features
### Pattern Recognition
* Common technique combinations
* Campaign correlation
* Actor attribution
* Similar incidents
### Impact Assessment
* Technique severity
* Asset scope
* Business impact
* Risk scoring
## Visualization
### Matrix View
* ATT\&CK matrix navigation
* Technique highlighting
* Sub-technique expansion
* Coverage mapping
### Timeline View
* Technique execution order
* Time-based correlation
* Pattern identification
* Campaign tracking
## Best Practices
1. **Technique Mapping**
* Verify technique matches
* Document evidence clearly
* Set appropriate confidence
* Link to observables
2. **Documentation**
* Detail procedure specifics
* Include context
* Reference sources
* Update findings
3. **Analysis**
* Look for patterns
* Compare with known actors
* Assess impact
* Plan mitigations
## Next Steps
Find related alerts
Get AI-powered analysis
# Alert Analytics
Source: https://docs.casebender.com/en/analytics/alert-analytics
Monitor and analyze security alerts with comprehensive metrics and visualizations.
## Overview
The Alert Analytics dashboard provides detailed insights into your security alerts:
!\[Alert Analytics Dashboard]
*Screenshot showing the main alert analytics dashboard*
## Key Metrics
### Total Alerts
* Total number of alerts
* Trend over time
* Percentage changes
* Alert volume patterns
!\[Total Alerts Card]
*Screenshot showing the total alerts metric card*
### Alert Status Distribution
View alerts by status:
* New alerts
* In Progress
* Imported
* Duplicated
* False Positive
* Ignored
!\[Alert Status Distribution]
*Screenshot showing the pie chart of alert status distribution*
### Alert Trend Analysis
Track alert patterns over time:
* Daily alert volumes
* Weekly trends
* Monthly comparisons
* Custom date ranges
!\[Alert Trend Chart]
*Screenshot showing the alert trend line chart*
### Severity Analysis
Monitor alerts by severity level:
* Critical alerts
* High severity
* Medium severity
* Low severity
Each severity level shows:
* Current count
* Historical trend
* Pattern analysis
* Impact assessment
!\[Severity Analysis]
*Screenshot showing the severity analysis charts*
### Top Alert Tags
View most common alert tags:
* Tag frequency
* Usage patterns
* Category distribution
* Trend analysis
!\[Top Tags Chart]
*Screenshot showing the top alert tags bar chart*
## Interactive Features
### Date Range Selection
Filter data by time period:
* Last 7 days
* Last 30 days
* Last 90 days
* Custom range
* Real-time updates
### Export Options
Export your analytics:
* PDF reports
* CSV data export
* Scheduled exports
* Custom formatting
### Visualization Controls
Customize your view:
* Chart types
* Data grouping
* Sorting options
* Filter controls
## Best Practices
### 1. Regular Monitoring
* Check daily volumes
* Track severity trends
* Monitor false positives
* Analyze patterns
### 2. Performance Analysis
* Response times
* Resolution rates
* Team efficiency
* Quality metrics
### 3. Trend Analysis
* Identify patterns
* Predict volumes
* Plan resources
* Optimize workflows
### 4. Report Generation
* Schedule reports
* Share insights
* Document findings
* Track progress
## Related Documentation
* [Case Analytics](./case-analytics.mdx)
* [Task Analytics](./task-analytics.mdx)
* [Analyst Performance](./analyst-performance.mdx)
# Analyst Performance
Source: https://docs.casebender.com/en/analytics/analyst-performance
Track and analyze individual and team performance metrics for security analysts.
## Overview
The Analyst Performance dashboard provides insights into individual and team performance:
!\[Analyst Performance Dashboard]
*Screenshot showing the main analyst performance dashboard*
## Key Metrics
### Cases Resolved
Track case resolution metrics:
* Total cases resolved
* Resolution rate
* Time to resolution
* Case complexity
!\[Cases Resolved Card]
*Screenshot showing the cases resolved metric card*
### Alerts Processed
Monitor alert handling:
* Total alerts processed
* Processing rate
* Alert types
* False positive rate
!\[Alerts Processed Card]
*Screenshot showing the alerts processed metric card*
### Average Response Time
Measure response efficiency:
* Initial response time
* Resolution time
* SLA compliance
* Time by priority
!\[Response Time Card]
*Screenshot showing the average response time metric card*
### Accuracy Rate
Track quality metrics:
* Decision accuracy
* False positive identification
* Quality assessment
* Improvement trends
!\[Accuracy Rate Card]
*Screenshot showing the accuracy rate metric card*
## Performance Analysis
### Individual Metrics
Track per-analyst performance:
* Workload distribution
* Specialization areas
* Efficiency metrics
* Quality indicators
### Team Metrics
Monitor team performance:
* Team capacity
* Collaboration patterns
* Knowledge sharing
* Resource utilization
## Best Practices
### 1. Performance Monitoring
* Regular reviews
* Goal tracking
* Skill development
* Process improvement
### 2. Quality Management
* Accuracy tracking
* Error analysis
* Training needs
* Best practices sharing
### 3. Resource Optimization
* Workload balancing
* Skill matching
* Capacity planning
* Team coordination
### 4. Continuous Improvement
* Performance feedback
* Training programs
* Process optimization
* Team development
## Related Documentation
* [Alert Analytics](./alert-analytics.mdx)
* [Case Analytics](./case-analytics.mdx)
* [Task Analytics](./task-analytics.mdx)
# Case Analytics
Source: https://docs.casebender.com/en/analytics/case-analytics
Track and analyze case management metrics with comprehensive visualizations and insights.
## Overview
The Case Analytics dashboard provides detailed insights into your case management:
!\[Case Analytics Dashboard]
*Screenshot showing the main case analytics dashboard*
## Key Metrics
### Total Cases
* Total number of cases
* Trend over time
* Percentage changes
* Case volume patterns
!\[Total Cases Card]
*Screenshot showing the total cases metric card*
### Case Status Distribution
View cases by status:
* New cases
* In Progress
* Under Review
* Resolved
* Closed
* Blocked
!\[Case Status Distribution]
*Screenshot showing the pie chart of case status distribution*
### Case Trend Analysis
Track case patterns over time:
* Daily case volumes
* Weekly trends
* Monthly comparisons
* Custom date ranges
!\[Case Trend Chart]
*Screenshot showing the case trend line chart*
### Severity Analysis
Monitor cases by severity level:
* Critical cases
* High severity
* Medium severity
* Low severity
Each severity level shows:
* Current count
* Historical trend
* Pattern analysis
* Impact assessment
!\[Severity Analysis]
*Screenshot showing the severity analysis charts*
### Top Case Tags
View most common case tags:
* Tag frequency
* Usage patterns
* Category distribution
* Trend analysis
!\[Top Tags Chart]
*Screenshot showing the top case tags bar chart*
## Interactive Features
### Date Range Selection
Filter data by time period:
* Last 7 days
* Last 30 days
* Last 90 days
* Custom range
* Real-time updates
### Export Options
Export your analytics:
* PDF reports
* CSV data export
* Scheduled exports
* Custom formatting
### Visualization Controls
Customize your view:
* Chart types
* Data grouping
* Sorting options
* Filter controls
## Best Practices
### 1. Regular Monitoring
* Check case volumes
* Track severity trends
* Monitor resolution times
* Analyze patterns
### 2. Performance Analysis
* Resolution rates
* Response times
* Team efficiency
* Quality metrics
### 3. Trend Analysis
* Identify patterns
* Predict volumes
* Plan resources
* Optimize workflows
### 4. Report Generation
* Schedule reports
* Share insights
* Document findings
* Track progress
## Related Documentation
* [Alert Analytics](./alert-analytics.mdx)
* [Task Analytics](./task-analytics.mdx)
* [Analyst Performance](./analyst-performance.mdx)
# Analytics
Source: https://docs.casebender.com/en/analytics/introduction
Comprehensive analytics and reporting features for monitoring alerts, cases, tasks, and analyst performance.
## Overview
The Analytics section provides detailed insights and metrics across different aspects of your security operations:
!\[Analytics Dashboard]
*Screenshot showing the main analytics dashboard with various metric cards*
## Available Dashboards
### 1. Alert Analytics
Monitor and analyze security alerts:
* Total alerts and trends
* Alert status distribution
* Severity breakdown
* Alert response times
* Top alert tags
!\[Alert Analytics]
*Screenshot showing the alert analytics dashboard*
### 2. Case Analytics
Track case management metrics:
* Case volume and trends
* Status distribution
* Severity levels
* Resolution times
* Case categories
!\[Case Analytics]
*Screenshot showing the case analytics dashboard*
### 3. Task Analytics
Monitor task performance:
* Task completion rates
* Priority distribution
* Time tracking
* Team workload
* Task dependencies
!\[Task Analytics]
*Screenshot showing the task analytics dashboard*
### 4. Analyst Performance
Track individual and team performance:
* Cases resolved
* Alerts processed
* Average response time
* Accuracy rate
* Team efficiency
!\[Analyst Performance]
*Screenshot showing the analyst performance dashboard*
## Common Features
### 1. Date Range Selection
Filter data by time period:
* Last 7 days
* Last 30 days
* Last 90 days
* Custom range
* Real-time updates
### 2. Export Options
Export your analytics:
* PDF reports
* Data download
* Scheduled reports
* Custom formats
### 3. Visualization Types
Analyze data through various charts:
* Line charts for trends
* Pie charts for distribution
* Bar charts for comparisons
* Heat maps for patterns
### 4. Interactive Elements
Interact with your data:
* Drill-down capabilities
* Filters and sorting
* Dynamic updates
* Custom views
## Best Practices
### 1. Regular Monitoring
* Check dashboards daily
* Track key metrics
* Identify trends
* Address anomalies
### 2. Performance Analysis
* Compare time periods
* Evaluate team metrics
* Monitor SLAs
* Track improvements
### 3. Report Generation
* Schedule regular reports
* Share key findings
* Document insights
* Track progress
### 4. Data-Driven Decisions
* Use metrics for planning
* Identify bottlenecks
* Optimize workflows
* Allocate resources
## Next Sections
* [Alert Analytics](./alert-analytics.mdx)
* [Case Analytics](./case-analytics.mdx)
* [Task Analytics](./task-analytics.mdx)
* [Analyst Performance](./analyst-performance.mdx)
# Task Analytics
Source: https://docs.casebender.com/en/analytics/task-analytics
Monitor and analyze task performance with comprehensive metrics and visualizations.
## Overview
The Task Analytics dashboard provides detailed insights into your task management:
!\[Task Analytics Dashboard]
*Screenshot showing the main task analytics dashboard*
## Key Metrics
### Total Tasks
* Total number of tasks
* Trend over time
* Percentage changes
* Task volume patterns
!\[Total Tasks Card]
*Screenshot showing the total tasks metric card*
### Task Status Distribution
View tasks by status:
* Open tasks
* In Progress
* Under Review
* Completed
* Blocked
* Cancelled
!\[Task Status Distribution]
*Screenshot showing the pie chart of task status distribution*
### Task Priority Analysis
Monitor tasks by priority level:
* High priority
* Medium priority
* Low priority
Each priority level shows:
* Current count
* Historical trend
* Completion rate
* Time tracking
!\[Priority Analysis]
*Screenshot showing the priority analysis charts*
### Completion Rate
Track task completion metrics:
* Daily completion rate
* Weekly trends
* Monthly averages
* Time to completion
!\[Completion Rate Chart]
*Screenshot showing the completion rate bar chart*
## Interactive Features
### Date Range Selection
Filter data by time period:
* Last 7 days
* Last 30 days
* Last 90 days
* Custom range
* Real-time updates
### Export Options
Export your analytics:
* PDF reports
* CSV data export
* Scheduled exports
* Custom formatting
### Visualization Controls
Customize your view:
* Chart types
* Data grouping
* Sorting options
* Filter controls
## Best Practices
### 1. Regular Monitoring
* Check task volumes
* Track priority trends
* Monitor completion rates
* Analyze patterns
### 2. Performance Analysis
* Completion times
* Response times
* Team efficiency
* Quality metrics
### 3. Trend Analysis
* Identify patterns
* Predict volumes
* Plan resources
* Optimize workflows
### 4. Report Generation
* Schedule reports
* Share insights
* Document findings
* Track progress
## Related Documentation
* [Alert Analytics](./alert-analytics.mdx)
* [Case Analytics](./case-analytics.mdx)
* [Analyst Performance](./analyst-performance.mdx)
# Create Alert
Source: https://docs.casebender.com/en/api-reference/endpoint/alert/alert-create
POST /alerts
Create a new alert
# Delete Alert
Source: https://docs.casebender.com/en/api-reference/endpoint/alert/delete
DELETE /alerts/{id}
Soft delete an alert
# Get Alerts
Source: https://docs.casebender.com/en/api-reference/endpoint/alert/get
GET /alerts
Search and list alerts with filters and pagination
# Get Alert by Id
Source: https://docs.casebender.com/en/api-reference/endpoint/alert/get-by-id
Get /alerts/{id}
Retrieve a specific alert by its ID
# Merge Alert with Case
Source: https://docs.casebender.com/en/api-reference/endpoint/alert/merge-alert-with-case
POST /alerts/{alertId}/merge/{caseId}
# Get Alert Statistics
Source: https://docs.casebender.com/en/api-reference/endpoint/alert/stats
GET /alerts/stats
Get aggregated statistics about alerts
# Update Alert
Source: https://docs.casebender.com/en/api-reference/endpoint/alert/update
PUT /alerts/{id}
Update an existing alert
# Create Case
Source: https://docs.casebender.com/en/api-reference/endpoint/case/create
POST /cases
Create a new case
# Delete Case
Source: https://docs.casebender.com/en/api-reference/endpoint/case/delete
DELETE /cases/{id}
Delete a case (soft delete)
# Search Cases
Source: https://docs.casebender.com/en/api-reference/endpoint/case/get
GET /cases
Search and list cases with filters and pagination
# Get Case
Source: https://docs.casebender.com/en/api-reference/endpoint/case/get-by-id
GET /cases/{id}
Retrieve a specific case by its ID
# Get Case Statistics
Source: https://docs.casebender.com/en/api-reference/endpoint/case/stats
GET /cases/stats
Get aggregate statistics for cases
# Update Case
Source: https://docs.casebender.com/en/api-reference/endpoint/case/update
PUT /cases/{id}
Update an existing case. Status changes to 'Closed' require all mandatory tasks to be completed unless X-Skip-Mandatory-Validation header is set with admin privileges.
# Add Alert Comment
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/alert-comments-add
POST /alerts/{alertId}/comments
Add a new comment to an alert
# Get Alert Comments
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/alert-comments-get
GET /alerts/{alertId}/comments
Get all comments for a specific alert
# Add Case Comment
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/case-comments-add
POST /cases/{caseId}/comments
Add a new comment to a case
# Get Case Comments
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/case-comments-get
GET /cases/{caseId}/comments
Get all comments for a specific case
# Detailed Health Check
Source: https://docs.casebender.com/en/api-reference/endpoint/health/detailed
GET /health/detailed
Get detailed health information including metrics
# Liveness Probe
Source: https://docs.casebender.com/en/api-reference/endpoint/health/liveness
GET /health
Check if the API service is running
# Readiness Probe
Source: https://docs.casebender.com/en/api-reference/endpoint/health/readiness
GET /health/ready
Check if the API service is ready to accept traffic
# Get Case Observables
Source: https://docs.casebender.com/en/api-reference/endpoint/observables/case-observables
GET /cases/{caseId}/observables
Get all observables for a specific case
# Create Observable
Source: https://docs.casebender.com/en/api-reference/endpoint/observables/create
POST /observables
Create a new observable/IOC
# Delete Observable
Source: https://docs.casebender.com/en/api-reference/endpoint/observables/delete
DELETE /observables/{id}
Delete an observable
# Get Observable by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/observables/get-by-id
GET /observables/{id}
Retrieve a specific observable
# List Observables
Source: https://docs.casebender.com/en/api-reference/endpoint/observables/list
GET /observables
List all observables with optional filters
# Get Observable Types
Source: https://docs.casebender.com/en/api-reference/endpoint/observables/types
GET /observable-types
Get list of available observable types
# Update Observable
Source: https://docs.casebender.com/en/api-reference/endpoint/observables/update
PUT /observables/{id}
Update an existing observable
# Get Case Tasks
Source: https://docs.casebender.com/en/api-reference/endpoint/task/case-tasks
GET /cases/{caseId}/tasks
Get all tasks for a specific case
# Create Task
Source: https://docs.casebender.com/en/api-reference/endpoint/task/create
POST /task
# Delete Task
Source: https://docs.casebender.com/en/api-reference/endpoint/task/delete
DELETE /task/{id}
# Get External Ticket
Source: https://docs.casebender.com/en/api-reference/endpoint/task/external-ticket-get
GET /tasks/{id}/external-ticket
Get the linked external ticket (ServiceNow/Jira) for a task (FUNC-038)
# Get Task by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/task/get-by-id
GET /tasks/{id}
Retrieve a specific task
# Create Jira Issue
Source: https://docs.casebender.com/en/api-reference/endpoint/task/jira-create
POST /tasks/{id}/external-ticket/jira
Create a Jira issue from a task with auto-populated data (FUNC-038)
# List Tasks
Source: https://docs.casebender.com/en/api-reference/endpoint/task/list
GET /tasks
List all tasks with optional filters including team assignment (FUNC-045)
# Create ServiceNow Ticket
Source: https://docs.casebender.com/en/api-reference/endpoint/task/servicenow-create
POST /tasks/{id}/external-ticket/servicenow
Create a ServiceNow incident from a task with auto-populated data (FUNC-038)
# Update Task
Source: https://docs.casebender.com/en/api-reference/endpoint/task/update
PUT /tasks/{id}
Update an existing task including team assignments (FUNC-045) and TLP classification (FUNC-044). TLP can only be elevated (increased), not lowered below the parent case's TLP level.
# Introduction
Source: https://docs.casebender.com/en/api-reference/introduction
CaseBender API endpoints
View the OpenAPI specification file
## Authentication
All API endpoints require authentication using API keys. Include your API key in every request using one of the following methods:
### Recommended: Bearer Token
Include your API key as a Bearer token in the `Authorization` header:
```bash theme={null}
Authorization: Bearer cbr_live_your_api_key_here
```
### Alternative: X-Api-Key Header
You can also use the `X-Api-Key` header:
```bash theme={null}
X-Api-Key: cbr_live_your_api_key_here
```
**Important**: Your API key grants access to your CaseBender instance. Keep it secure and never share it publicly.
### Creating API Keys
To create API keys:
1. Log in to your CaseBender instance
2. Navigate to **Account** → **API Keys**
3. Click **Create API Key**
4. Configure the key name, description, tier, and scopes
5. **Save the key immediately** - it is displayed only once and cannot be retrieved later
When you create an API key, you'll receive a single key that looks like:
```
cbr_live_a1b2c3d4e5f6g7h8i9j0...
```
### Using API Keys
Include the API key in all API requests:
#### Using cURL
```bash theme={null}
curl -X GET https://your-instance.casebender.com/api/v1/alerts \
-H "Authorization: Bearer YOUR_API_KEY_HERE" \
-H "Content-Type: application/json"
```
#### Using Python (requests library)
```python theme={null}
import requests
headers = {
"Authorization": "Bearer YOUR_API_KEY_HERE",
"Content-Type": "application/json"
}
response = requests.get(
"https://your-instance.casebender.com/api/v1/alerts",
headers=headers
)
```
#### Using JavaScript/Node.js (fetch)
```javascript theme={null}
const response = await fetch(
"https://your-instance.casebender.com/api/v1/alerts",
{
method: "GET",
headers: {
"Authorization": "Bearer YOUR_API_KEY_HERE",
"Content-Type": "application/json",
},
}
);
```
### API Key Tiers
API keys are assigned tiers that determine rate limits:
| Tier | Requests/Minute | Requests/Hour | Burst Allowance |
| ------------ | --------------- | ------------- | --------------- |
| Basic | 60 | 1,000 | 10 |
| Standard | 300 | 10,000 | 50 |
| Professional | 1,000 | 50,000 | 100 |
| Enterprise | 5,000 | 200,000 | 500 |
| Unlimited | No limit | No limit | No limit |
### API Key Scopes
When creating an API key, you can limit its access to specific operations:
* `alerts:read` - Read alerts
* `alerts:write` - Create and update alerts
* `cases:read` - Read cases
* `cases:write` - Create and update cases
* `observables:read` - Read observables
* `observables:write` - Create and update observables
* `users:read` - Read user information
* `admin:*` - Administrative operations
### Common Authentication Errors
* **401 Unauthorized**:
* Missing `Authorization` header
* Invalid or expired API key
* API key has been revoked or suspended
* **403 Forbidden**:
* API key lacks required scope for the operation
* TLP/PAP access restrictions
* **429 Too Many Requests**:
* Rate limit exceeded for your tier
### Security Best Practices
* **Never share your API key** - treat it like a password
* **Rotate API keys regularly** - revoke old keys and create new ones periodically
* **Use different keys for different applications** - this allows you to revoke access per application
* **Set expiration dates** - configure API keys to expire automatically when possible
* **Use minimum required scopes** - only grant the permissions your application needs
### Legacy Authentication (Deprecated)
The legacy `x-api-key` and `x-api-secret` headers are still supported for backward compatibility but are deprecated. Please migrate to Bearer token authentication.
```bash theme={null}
# Deprecated - do not use for new integrations
curl -X GET https://your-instance.casebender.com/api/v1/alerts \
-H "x-api-key: YOUR_ACCESS_KEY" \
-H "x-api-secret: YOUR_SECRET_KEY"
```
# Activity Logs
Source: https://docs.casebender.com/en/audits/activity-logs
Track and analyze user activities and system events with comprehensive activity logging.
## Overview
Activity Logs provide a detailed record of all user actions and system events:
!\[Activity Logs View]
*Screenshot showing the activity logs interface*
## Activity Types
### User Activities
Track user interactions:
* Login/logout events
* Data modifications
* Status changes
* Document access
* Configuration updates
### System Events
Monitor system operations:
* Automated processes
* System updates
* Integration events
* Background tasks
* Error events
## Activity Components
### Activity Records
Each activity record includes:
* Timestamp
* User information
* Action type
* Affected resources
* Change details
### Event Context
Capture event details:
* Source information
* Target resources
* Action parameters
* Result status
* Related data
### Activity Metadata
Additional context:
* IP address
* Browser/device
* Session information
* Location data
* Access method
## Visualization
### Timeline View
Chronological display of activities:
* Time-based ordering
* Activity grouping
* Visual indicators
* Filter options
* Search capabilities
### Activity Analytics
Analyze activity patterns:
* Usage trends
* Common actions
* Peak periods
* User behavior
* System performance
## Interactive Features
### 1. Filtering
Filter activities by:
* Date range
* Activity type
* User
* Resource
* Status
### 2. Search
Search through activities:
* Full-text search
* Advanced filters
* Custom queries
* Saved searches
* Quick filters
### 3. Export
Export activity records:
* PDF reports
* CSV exports
* Custom formats
* Scheduled exports
* Data selection
## Best Practices
### 1. Activity Monitoring
* Regular review
* Pattern analysis
* Anomaly detection
* Performance tracking
* Security monitoring
### 2. Data Retention
* Retention policies
* Archival strategy
* Storage optimization
* Data cleanup
* Compliance requirements
### 3. Security Analysis
* Access patterns
* Security events
* Threat detection
* Compliance monitoring
* Audit preparation
## Related Documentation
* [Change History](./change-history.mdx)
* [Status Tracking](./status-tracking.mdx)
* [Compliance Monitoring](./compliance-monitoring.mdx)
# Change History
Source: https://docs.casebender.com/en/audits/change-history
Track and analyze changes to alerts, cases, and system configurations with detailed change history.
## Overview
The Change History feature provides a detailed record of all modifications:
!\[Change History View]
*Screenshot showing the change history interface*
## Change Types
### Alert Changes
Track modifications to alerts:
* Status changes
* Severity updates
* Assignee changes
* Description edits
* Title modifications
* TLP/PAP changes
* Team updates
* Tag modifications
* Organization changes
* Custom field updates
### Case Changes
Monitor case modifications:
* Status transitions
* Assignment changes
* Priority updates
* Description edits
* Team changes
* Tag updates
* Custom field modifications
### System Changes
Track system-level changes:
* Configuration updates
* Integration changes
* Workflow modifications
* Permission updates
* Role assignments
## Change Details
### Change Records
Each change record includes:
* Change type
* Previous value
* New value
* Timestamp
* User information
* Change comments
### User Information
Track who made changes:
* User name
* Profile picture
* Email address
* Role information
* Team association
### Change Comments
Document change context:
* Change reasons
* Additional notes
* Related references
* Decision context
* Follow-up actions
## Visualization
### Timeline View
Chronological display of changes:
* Time-based ordering
* Visual indicators
* Change grouping
* Filter options
* Search capabilities
### Change Comparison
Compare changes visually:
* Side-by-side view
* Highlight differences
* Track modifications
* Show relationships
* Identify patterns
## Interactive Features
### 1. Filtering
Filter change history by:
* Date range
* Change type
* User
* Entity type
* Field changes
### 2. Search
Search through changes:
* Full-text search
* Advanced filters
* Custom queries
* Saved searches
* Quick filters
### 3. Export
Export change records:
* PDF reports
* CSV exports
* Custom formats
* Scheduled exports
* Data selection
## Best Practices
### 1. Change Documentation
* Add clear comments
* Provide context
* Link related changes
* Document decisions
* Include references
### 2. Change Review
* Regular audits
* Pattern analysis
* Anomaly detection
* Compliance checks
* Quality assurance
### 3. Change Management
* Follow procedures
* Document approvals
* Track dependencies
* Monitor impact
* Update documentation
## Related Documentation
* [Status Tracking](./status-tracking.mdx)
* [Activity Logs](./activity-logs.mdx)
* [Compliance Monitoring](./compliance-monitoring.mdx)
# Compliance Monitoring
Source: https://docs.casebender.com/en/audits/compliance-monitoring
Monitor and ensure compliance with regulatory requirements and internal policies through comprehensive auditing.
## Overview
Compliance Monitoring provides tools and features to track, analyze, and maintain regulatory compliance:
!\[Compliance Monitoring View]
*Screenshot showing the compliance monitoring interface*
## Compliance Features
### Policy Tracking
Monitor policy adherence:
* Policy requirements
* Compliance status
* Policy updates
* Exception tracking
* Violation alerts
### Regulatory Compliance
Track regulatory requirements:
* Regulatory frameworks
* Compliance standards
* Audit requirements
* Documentation needs
* Reporting obligations
## Monitoring Components
### Compliance Records
Each compliance record includes:
* Requirement details
* Status information
* Due dates
* Responsible parties
* Documentation links
### Assessment Data
Track compliance assessments:
* Evaluation criteria
* Assessment results
* Gap analysis
* Remediation plans
* Follow-up actions
### Documentation
Maintain compliance documents:
* Policy documents
* Procedures
* Evidence files
* Audit reports
* Certifications
## Visualization
### Dashboard View
Comprehensive compliance overview:
* Status indicators
* Risk levels
* Due dates
* Progress tracking
* Alert notifications
### Compliance Analytics
Analyze compliance data:
* Compliance rates
* Trend analysis
* Risk assessment
* Performance metrics
* Gap identification
## Interactive Features
### 1. Filtering
Filter compliance data by:
* Requirement type
* Status
* Due date
* Risk level
* Department
### 2. Search
Search compliance records:
* Full-text search
* Advanced filters
* Custom queries
* Saved searches
* Quick filters
### 3. Reporting
Generate compliance reports:
* Status reports
* Audit reports
* Gap analysis
* Risk assessments
* Executive summaries
## Best Practices
### 1. Regular Monitoring
* Scheduled reviews
* Status updates
* Risk assessments
* Gap analysis
* Action tracking
### 2. Documentation Management
* Version control
* Evidence collection
* Document organization
* Access control
* Retention policies
### 3. Risk Management
* Risk assessment
* Control testing
* Issue tracking
* Remediation planning
* Progress monitoring
## Related Documentation
* [Change History](./change-history.mdx)
* [Status Tracking](./status-tracking.mdx)
* [Activity Logs](./activity-logs.mdx)
# Audit Logs
Source: https://docs.casebender.com/en/audits/introduction
Track and monitor changes across alerts, cases, and system activities with comprehensive audit logging.
## Overview
The Audit Logs system provides detailed tracking of changes and activities across the platform:
!\[Audit Logs Dashboard]
*Screenshot showing the main audit logs interface*
## Key Features
### 1. Change Tracking
Monitor changes to:
* Alert status and severity
* Case assignments and updates
* Team modifications
* Organization changes
* Custom field updates
### 2. Status History
Track status transitions:
* Status changes
* Time in each status
* Change comments
* User attribution
* Timestamp tracking
### 3. Activity Logging
Record user activities:
* User actions
* System events
* Authentication events
* API access logs
* Integration activities
### 4. Compliance Tracking
Monitor compliance-related metrics:
* Resolution quality
* Compliance scores
* Risk assessments
* Time to resolution
* Trend analysis
## Audit Components
### Change History
Each audit entry includes:
* Previous and new values
* Change timestamp
* User information
* Change comments
* Related entities
### Status Tracking
Monitor status workflows:
* Status transitions
* Duration in status
* Status comments
* Workflow patterns
* Resolution paths
### User Attribution
Track user activities:
* Action performer
* Affected users
* Team changes
* Permission updates
* Role modifications
## Interactive Features
### 1. Filtering
Filter audit logs by:
* Date range
* User
* Action type
* Entity type
* Status changes
### 2. Export Options
Export audit data:
* PDF reports
* CSV exports
* Scheduled reports
* Custom formats
### 3. Search Capabilities
Search through logs:
* Full-text search
* Advanced filters
* Custom queries
* Saved searches
## Best Practices
### 1. Regular Review
* Monitor changes daily
* Review critical changes
* Track unusual patterns
* Investigate anomalies
### 2. Compliance Management
* Track required changes
* Monitor compliance
* Document reviews
* Maintain records
### 3. Security Monitoring
* Review access patterns
* Track authentication
* Monitor API usage
* Investigate alerts
### 4. Documentation
* Document changes
* Maintain history
* Track decisions
* Record comments
## Next Sections
* [Change History](./change-history.mdx)
* [Status Tracking](./status-tracking.mdx)
* [Activity Logs](./activity-logs.mdx)
* [Compliance Monitoring](./compliance-monitoring.mdx)
# Status Tracking
Source: https://docs.casebender.com/en/audits/status-tracking
Monitor and analyze status changes and transitions with comprehensive status history tracking.
## Overview
The Status Tracking feature provides detailed insights into status changes and time spent in each status:
!\[Status Tracking View]
*Screenshot showing the status tracking interface*
## Status History
### Status Changes
Track status transitions:
* Previous status
* New status
* Change timestamp
* User information
* Change comments
### Time Tracking
Monitor time in each status:
* Duration calculation
* Status breakdowns
* Time analytics
* Trend analysis
* SLA monitoring
## Status Components
### Status Records
Each status record includes:
* Status values
* Transition time
* Duration
* User attribution
* Comments
### User Information
Track who made status changes:
* User name
* Profile picture
* Role information
* Team association
* Change context
### Status Comments
Document status changes:
* Change reasons
* Additional notes
* Related issues
* Decision context
* Follow-up actions
## Visualization
### Timeline View
Chronological display of status:
* Time-based ordering
* Visual indicators
* Status grouping
* Filter options
* Search capabilities
### Status Analytics
Analyze status patterns:
* Time distribution
* Common transitions
* Bottleneck detection
* Efficiency metrics
* Trend analysis
## Interactive Features
### 1. Filtering
Filter status history by:
* Date range
* Status type
* User
* Duration
* Comments
### 2. Search
Search through status changes:
* Full-text search
* Advanced filters
* Custom queries
* Saved searches
* Quick filters
### 3. Export
Export status records:
* PDF reports
* CSV exports
* Custom formats
* Scheduled exports
* Data selection
## Best Practices
### 1. Status Documentation
* Add clear comments
* Provide context
* Document decisions
* Track dependencies
* Include references
### 2. Status Review
* Regular audits
* Pattern analysis
* Bottleneck detection
* Efficiency checks
* Process improvement
### 3. Time Management
* Monitor durations
* Track SLAs
* Identify delays
* Optimize workflows
* Improve efficiency
## Related Documentation
* [Change History](./change-history.mdx)
* [Activity Logs](./activity-logs.mdx)
* [Compliance Monitoring](./compliance-monitoring.mdx)
# AI Features in Case Management
Source: https://docs.casebender.com/en/cases/ai-features
This guide covers the AI-powered features available in the case management system, designed to enhance investigation efficiency and decision-making.
## Overview
AI features provide automated analysis, insights, and recommendations to help analysts work more effectively:
!\[AI Features Overview]
*Screenshot showing the AI features dashboard*
## AI Insights Tab
### Automated Analysis
The AI Insights tab provides:
1. **Case Summary**:
* Key findings
* Risk assessment
* Recommended actions
* Similar cases
2. **Pattern Detection**:
* Behavioral patterns
* Attack techniques
* Anomaly detection
* Trend analysis
!\[AI Insights Interface]
*Screenshot of the AI Insights tab showing analysis results*
## Key Features
### 1. Similar Case Detection
Automatically identifies related cases:
* Pattern matching
* Behavioral similarity
* Shared indicators
* Historical correlation
### 2. Threat Analysis
AI-powered threat assessment:
* Risk scoring
* Impact analysis
* Threat actor attribution
* Attack pattern matching
### 3. Recommendation Engine
Provides actionable recommendations:
* Next steps
* Investigation paths
* Mitigation strategies
* Resource allocation
### 4. Natural Language Processing
Advanced text analysis:
* Content summarization
* Entity extraction
* Relationship mapping
* Sentiment analysis
## Using AI Features
### Accessing AI Insights
1. Open a case
2. Navigate to AI Insights tab
3. View automated analysis
4. Explore recommendations
### Interpreting Results
Understanding AI outputs:
* Confidence scores
* Supporting evidence
* Related findings
* Action priorities
!\[AI Results Interpretation]
*Screenshot showing how to interpret AI analysis results*
## Configuration Options
### AI Feature Settings
Configure AI behavior:
* Analysis frequency
* Confidence thresholds
* Data sources
* Integration points
### Model Selection
Choose AI models for:
* Pattern recognition
* Text analysis
* Risk assessment
* Recommendation generation
!\[AI Configuration]
*Screenshot of AI feature configuration options*
## Integration Features
### External AI Services
Integration with:
* OpenAI services
* Custom ML models
* Third-party AI tools
* Threat intelligence platforms
### Data Sources
AI analysis uses:
* Case history
* Alert data
* Threat intelligence
* External feeds
## Best Practices
### 1. Data Quality
Ensure quality inputs:
* Complete case documentation
* Accurate metadata
* Relevant observables
* Clear descriptions
### 2. AI Assistance
Effective use of AI:
* Verify AI findings
* Combine with human analysis
* Document AI insights
* Provide feedback
### 3. Continuous Learning
Improve AI performance:
* Regular model updates
* Feedback integration
* Performance monitoring
* Training data updates
## Privacy and Security
### Data Protection
AI feature security:
* Data encryption
* Access controls
* Audit logging
* Privacy compliance
### Ethical Considerations
Responsible AI use:
* Bias prevention
* Decision transparency
* Human oversight
* Ethical guidelines
!\[Privacy Settings]
*Screenshot showing AI privacy and security settings*
## Performance Metrics
### AI Effectiveness
Track AI performance:
* Accuracy rates
* Time savings
* False positive rates
* User adoption
### Impact Analysis
Measure business impact:
* Resolution time
* Decision quality
* Resource efficiency
* Cost savings
## Troubleshooting
### Common Issues
Address AI-related problems:
1. **Analysis Delays**:
* Check data sources
* Verify API access
* Monitor system resources
2. **Accuracy Issues**:
* Review training data
* Adjust thresholds
* Update models
* Gather feedback
!\[Troubleshooting Guide]
*Screenshot showing AI troubleshooting interface*
## Future Developments
Upcoming AI features:
* Advanced analytics
* Predictive modeling
* Automated reporting
* Enhanced visualization
For more information about working with cases, see [Working with Cases](./working-with-cases.mdx).
# Creating Cases
Source: https://docs.casebender.com/en/cases/creating-cases
This guide explains the different ways to create cases in the system and the available options during case creation.
## Methods of Creation
### 1. Manual Creation
Cases can be created manually through the user interface in several ways:
* Using the "New Case" button in the cases list view
* From the quick actions menu in the navigation bar
* Through the case templates in the settings
!\[Create Case Dialog]
*Screenshot showing the case creation dialog with all available fields*
### 2. From Templates
Case templates provide a standardized way to create cases with predefined fields:
* Choose from available templates or start with a blank case
* Templates can include pre-filled fields and default values
* Organization-specific templates are supported
!\[Case Templates]
*Screenshot showing the template selection dialog during case creation*
### 3. From Alerts
Cases can be automatically or manually created from security alerts:
* Convert single alerts to cases
* Merge multiple alerts into a single case
* Inherit alert properties (severity, TLP, etc.)
## Required Fields
When creating a case, the following fields are mandatory:
* **Title**: A clear, descriptive name for the case
* **Status**: Initial status (defaults to "New")
* **Severity**: Impact level (1-5)
* **TLP**: Traffic Light Protocol classification
* **PAP**: Permissible Actions Protocol level
## Optional Fields
Additional fields that can be specified during creation:
* **Description**: Detailed information about the case
* **Tags**: Custom labels for categorization
* **Assignee**: Team member responsible for the case
* **Custom Fields**: Organization-specific data fields
* **Organizations**: Visibility settings for organizations
## Case Creation Settings
Administrators can configure various aspects of case creation:
* Default values for new cases
* Required and optional fields
* Available templates
* Automation rules for case creation
* Organization-specific settings
!\[Case Settings]
*Screenshot showing the administrative settings for case creation*
## Best Practices
1. **Titles**: Use clear, descriptive titles that include key information
2. **Templates**: Create templates for common case types to ensure consistency
3. **Severity**: Follow organization guidelines for severity assignment
4. **TLP/PAP**: Carefully consider information sharing restrictions
5. **Custom Fields**: Use custom fields to capture organization-specific data
## Automation Options
Cases can be created automatically through various triggers:
* Alert-based triggers
* Integration webhooks
* API endpoints
* Scheduled workflows
## Next Steps
After creating a case:
1. Add relevant observables and artifacts
2. Create initial tasks
3. Link related alerts
4. Assign team members
5. Add detailed documentation
For more information on working with cases after creation, see [Working with Cases](./working-with-cases.mdx).
# Case Management
Source: https://docs.casebender.com/en/cases/introduction
The Case Management system is a comprehensive solution for tracking, managing, and resolving security incidents and investigations. This documentation covers all aspects of the case management functionality.
## Overview
Cases are the core entities for managing security incidents, investigations, and related activities. Each case represents a distinct security event or investigation that needs to be tracked and resolved.
!\[Case List View]
*Screenshot showing the main case list view with filters, search, and case cards*
## Key Features
* **Case Lifecycle Management**: Track cases from creation to resolution
* **Customizable Status Workflows**: Configure case statuses to match your organization's processes
* **Team Collaboration**: Assign cases to team members and track their progress
* **Rich Metadata**: Track severity, TLP (Traffic Light Protocol), and PAP (Permissible Actions Protocol)
* **Tagging System**: Organize cases with customizable tags
* **Integration with Alerts**: Link related alerts to cases
* **AI Insights**: Automated analysis and insights for cases (when enabled)
* **Audit Trail**: Complete timeline of case activities and changes
## Case Properties
### Core Properties
* **Case ID**: Unique identifier (auto-generated)
* **Title**: Descriptive name of the case
* **Description**: Detailed information about the case
* **Status**: Current state in the workflow (New, InProgress, Closed)
* **Severity**: Impact level (1-5)
* **TLP**: Traffic Light Protocol classification
* **PAP**: Permissible Actions Protocol level
* **Tags**: Custom labels for categorization
* **Custom Fields**: Organization-specific additional data
### Metadata
* **Created By**: User who created the case
* **Created At**: Timestamp of case creation
* **Updated At**: Last modification timestamp
* **Assigned To**: Team member responsible for the case
* **Organizations**: Associated organizations (for multi-tenant setups)
## Related Components
Cases are connected to several other components:
* **Alerts**: Security alerts that triggered or are related to the case
* **Observables**: Artifacts and indicators associated with the case
* **Tasks**: Action items and to-dos within the case
* **TTPs**: Tactics, Techniques, and Procedures identified in the case
* **Timeline**: Chronological record of case activities
* **AI Insights**: AI-powered analysis and recommendations (if enabled)
!\[Case Detail View]
*Screenshot showing the detailed view of a case with all its components and tabs*
## Next Sections
* [Creating Cases](./creating-cases.mdx)
* [Case Workflows](./workflows.mdx)
* [Working with Cases](./working-with-cases.mdx)
* [Case Settings](./settings.mdx)
* [AI Features](./ai-features.mdx)
# Case Settings
Source: https://docs.casebender.com/en/cases/settings
This guide covers the configuration options and settings available for customizing the case management system.
## Access Settings
Navigate to Settings > Cases to configure case-related options:
!\[Case Settings Page]
*Screenshot showing the main case settings interface*
## Status Configuration
### Managing Case Statuses
Configure the available case statuses:
1. **Create Status**:
* Label and description
* Color coding
* Stage assignment
* Unique value
2. **Edit Status**:
* Modify existing status properties
* Update color and label
* Change stage assignment
3. **Delete Status**:
* Remove unused statuses
* Handle cases with deleted status
!\[Status Management]
*Screenshot of the status management interface*
## Templates
### Case Templates
Create and manage case templates:
* Define default values
* Set required fields
* Create specialized templates
* Organization-specific templates
### Template Properties
Configure for each template:
* Name and description
* Default field values
* Required fields
* Automation rules
* Team assignments
!\[Template Configuration]
*Screenshot showing template creation and editing*
## Field Configuration
### Custom Fields
Add organization-specific fields:
* Field types (text, number, date, etc.)
* Required/optional settings
* Default values
* Field validation
### Field Display
Configure how fields appear:
* Field order
* Grouping
* Visibility conditions
* Mobile display
!\[Custom Fields]
*Screenshot of custom field configuration*
## Automation Settings
### Workflow Rules
Configure automated actions:
1. **Triggers**:
* Case creation
* Status changes
* Field updates
* Time-based events
2. **Actions**:
* Status updates
* Assignments
* Notifications
* Integration calls
!\[Workflow Automation]
*Screenshot of workflow automation settings*
## Team Settings
### Access Control
Configure team-based settings:
* Role permissions
* Team assignments
* Visibility rules
* Collaboration settings
### Assignment Rules
Set up case assignment rules:
* Auto-assignment
* Load balancing
* Skill-based routing
* Backup assignments
!\[Team Configuration]
*Screenshot showing team and assignment settings*
## Integration Settings
### External Systems
Configure integrations with:
* SIEM platforms
* Ticketing systems
* Communication tools
* Custom applications
### API Configuration
Manage API settings:
* API keys
* Webhook endpoints
* Rate limits
* Authentication
!\[Integration Settings]
*Screenshot of integration configuration*
## Notification Settings
### Email Notifications
Configure email alerts for:
* Case creation
* Status changes
* Assignments
* Comments
* Due dates
### Other Notifications
Set up notifications for:
* Slack/Teams
* Mobile push
* Custom webhooks
* System alerts
!\[Notification Configuration]
*Screenshot showing notification settings*
## Analytics Settings
### Metrics Configuration
Configure tracking for:
* Response times
* Resolution rates
* Team performance
* Custom metrics
### Reporting
Set up report templates:
* Case summaries
* Team reports
* Custom reports
* Scheduled reports
!\[Analytics Settings]
*Screenshot of analytics and reporting configuration*
## Best Practices
1. **Status Management**:
* Keep status list concise
* Use clear color coding
* Document status meanings
2. **Templates**:
* Create templates for common cases
* Review and update regularly
* Get team feedback
3. **Fields**:
* Only add necessary fields
* Use clear field labels
* Group related fields
4. **Automation**:
* Start with simple rules
* Test thoroughly
* Monitor performance
5. **Permissions**:
* Follow least privilege
* Regular access review
* Document role requirements
For information about working with cases, see [Working with Cases](./working-with-cases.mdx).
# Case Workflows
Source: https://docs.casebender.com/en/cases/workflows
Case workflows define how cases progress through your organization's incident response or investigation process. This guide explains how to work with and customize case workflows.
## Case Status Stages
Cases can be in one of three main stages:
1. **New**: Recently created cases requiring initial triage
2. **InProgress**: Cases actively being worked on
3. **Closed**: Resolved or completed cases
!\[Case Status Flow]
*Diagram showing the progression of cases through different status stages*
## Customizable Status Labels
Within each stage, organizations can create custom status labels:
* **New Stage**: Initial Triage, Pending Review, etc.
* **InProgress Stage**: Investigating, Waiting for Response, etc.
* **Closed Stage**: Resolved, False Positive, etc.
### Status Properties
Each status has the following properties:
* **Label**: Display name for the status
* **Color**: Visual indicator for the status
* **Stage**: Associated workflow stage
* **Can Delete**: Whether the status can be removed
* **Value**: Unique identifier for the status
!\[Status Management]
*Screenshot of the status management interface in settings*
## Workflow Automation
### Triggers
Workflows can be automated based on various triggers:
* **CaseCreated**: When a new case is created
* **CaseUpdated**: When case properties are modified
* **CaseDeleted**: When a case is removed
### Actions
Automated actions can include:
* Status changes
* Assignment updates
* Notification generation
* Integration with external systems
* Custom script execution
## Status Transitions
### Manual Transitions
Users can manually change case status based on their permissions:
* From the case detail view
* Through bulk actions in the case list
* Via the API
### Automated Transitions
Status can change automatically based on:
* Time-based rules
* Alert updates
* External system triggers
* Workflow automation rules
## Permissions and Roles
Status management is controlled by user permissions:
* **caseUpdate**: Required to change case status
* **caseCreate**: Needed to set initial status
* **caseDelete**: Required for certain status transitions
## Workflow Analytics
Track and analyze your case workflows:
* Time in each status
* Common transition patterns
* Bottlenecks and delays
* Team performance metrics
!\[Workflow Analytics]
*Screenshot showing workflow analytics dashboard*
## Best Practices
1. **Status Clarity**: Use clear, descriptive status names
2. **Color Coding**: Choose distinct colors for different stages
3. **Automation**: Automate routine status changes
4. **Metrics**: Monitor time spent in each status
5. **Documentation**: Maintain clear status transition guidelines
## Configuration
### Adding New Status
1. Navigate to Case Status settings
2. Click "Add Status"
3. Configure properties:
* Label
* Stage
* Color
* Value
4. Save changes
### Modifying Workflows
1. Access Workflow settings
2. Create or edit workflow rules
3. Define triggers and actions
4. Test workflow automation
5. Deploy changes
## Integration
Workflow status can integrate with:
* External ticketing systems
* SIEM platforms
* Communication tools
* Custom applications
For more information on working with cases, see [Working with Cases](./working-with-cases.mdx).
# Working with Cases
Source: https://docs.casebender.com/en/cases/working-with-cases
This guide covers the day-to-day operations and features available when working with cases in the system.
## Case Detail View
The case detail view is your primary workspace for managing cases:
!\[Case Detail Interface]
*Screenshot showing the main case detail interface with all components*
### Key Areas
1. **Header**: Case title, ID, and quick actions
2. **Details Panel**: Core case properties and metadata
3. **Tabs**: Access different case components
4. **Activity Timeline**: Recent updates and changes
## Case Components
### 1. Tasks
Tasks help track action items within a case:
* Create and assign tasks
* Set priorities and due dates
* Track task completion
* Add task notes and attachments
!\[Tasks Tab]
*Screenshot of the tasks management interface*
### 2. Observables
Manage artifacts and indicators:
* Add files, IPs, domains, and other observables
* Automatic enrichment
* Relationship visualization
* Threat intelligence lookup
!\[Observables Tab]
*Screenshot showing observable management and analysis*
### 3. TTPs (Tactics, Techniques, and Procedures)
Map case activities to known attack patterns:
* MITRE ATT\&CK® framework integration
* Custom TTP definitions
* Visual attack flow mapping
* Related procedure documentation
!\[TTPs Tab]
*Screenshot of the TTP mapping interface*
### 4. Timeline
Chronological view of case activities:
* Automatic event tracking
* Manual timeline entries
* Filter and search capabilities
* Evidence timeline reconstruction
!\[Timeline Tab]
*Screenshot showing the case timeline view*
### 5. AI Insights
AI-powered analysis and recommendations:
* Automated case analysis
* Similar case detection
* Recommendation engine
* Pattern recognition
!\[AI Insights Tab]
*Screenshot of AI-powered insights and recommendations*
## Case Actions
### Assignment and Collaboration
* Assign cases to team members
* Transfer ownership
* Add collaborators
* Team notifications
### Linking and Relationships
* Link related cases
* Connect alerts
* Establish observable relationships
* Create case groups
### Documentation
* Add notes and comments
* Attach files and evidence
* Generate reports
* Export case data
### Case Merging
When multiple cases are related:
1. Select cases to merge
2. Choose primary case
3. Review relationships
4. Confirm merge action
## Analysis Tools
### 1. Search and Filters
* Full-text search
* Advanced filtering
* Saved searches
* Custom views
### 2. Visualizations
* Relationship graphs
* Timeline views
* Statistical analysis
* Custom dashboards
### 3. Reporting
* Case summaries
* Status reports
* Team metrics
* Custom report templates
## Best Practices
1. **Documentation**: Keep detailed notes and updates
2. **Observables**: Add context to all observables
3. **Tasks**: Break down complex investigations
4. **Timeline**: Document key findings and decisions
5. **Collaboration**: Use comments for team communication
## Keyboard Shortcuts
Common actions have keyboard shortcuts:
* `Ctrl/Cmd + S`: Save changes
* `Ctrl/Cmd + E`: Edit mode
* `Ctrl/Cmd + F`: Search
* `Esc`: Cancel/Close
## Mobile Access
The case interface is responsive and supports:
* Mobile viewing
* Basic editing
* Task management
* Status updates
!\[Mobile Interface]
*Screenshot showing the mobile case interface*
## Integration Features
Cases integrate with:
* Email notifications
* Slack/Teams messages
* Webhook triggers
* External systems
For information about case workflows and status management, see [Case Workflows](./workflows.mdx).
# Deploy to AWS
Source: https://docs.casebender.com/en/deployment/aws
Deploy CaseBender on Amazon Web Services (AWS)
## Overview
This guide walks you through deploying CaseBender on AWS using pre-built Docker images with Amazon ECS (Elastic Container Service) and Fargate.
## Prerequisites
1. [AWS Account](https://aws.amazon.com/)
2. [AWS CLI](https://aws.amazon.com/cli/) installed and configured
3. [Docker](https://docs.docker.com/get-docker/) installed
## Step 1: Initial Setup
### Install and Configure AWS CLI
```bash macOS theme={null}
# Using Homebrew
brew install awscli
# Configure AWS CLI
aws configure
# Configure Docker for ECR
aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin $(aws sts get-caller-identity --query Account --output text).dkr.ecr.us-east-1.amazonaws.com
```
```bash Linux theme={null}
# Install AWS CLI
curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
unzip awscliv2.zip
sudo ./aws/install
# Configure AWS CLI
aws configure
# Configure Docker for ECR
aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin $(aws sts get-caller-identity --query Account --output text).dkr.ecr.us-east-1.amazonaws.com
```
```powershell Windows theme={null}
# Download and run the AWS CLI MSI installer
# https://awscli.amazonaws.com/AWSCLIV2.msi
# Configure AWS CLI
aws configure
# Configure Docker for ECR
aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin $(aws sts get-caller-identity --query Account --output text).dkr.ecr.us-east-1.amazonaws.com
```
## Step 2: Set Up AWS Infrastructure
### Create S3 Bucket for Storage
```bash theme={null}
# Create S3 bucket
aws s3 create-bucket \
--bucket casebender-storage \
--region us-east-1
# Enable versioning (optional)
aws s3api put-bucket-versioning \
--bucket casebender-storage \
--versioning-configuration Status=Enabled
# Create IAM user for S3 access
aws iam create-user --user-name casebender-storage-user
# Create and attach policy
aws iam create-policy \
--policy-name casebender-storage-policy \
--policy-document '{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::casebender-storage",
"arn:aws:s3:::casebender-storage/*"
]
}
]
}'
# Attach policy to user
aws iam attach-user-policy \
--user-name casebender-storage-user \
--policy-arn arn:aws:iam::YOUR_ACCOUNT_ID:policy/casebender-storage-policy
# Create access keys
aws iam create-access-key --user-name casebender-storage-user
```
### Create a VPC
```bash theme={null}
# Create VPC
aws ec2 create-vpc \
--cidr-block 10.0.0.0/16 \
--tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=casebender-vpc}]'
# Enable DNS hostnames
aws ec2 modify-vpc-attribute \
--vpc-id \
--enable-dns-hostnames
```
### Create Subnets
```bash theme={null}
# Create public subnets
aws ec2 create-subnet \
--vpc-id \
--cidr-block 10.0.1.0/24 \
--availability-zone us-east-1a \
--tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=casebender-public-1a}]'
aws ec2 create-subnet \
--vpc-id \
--cidr-block 10.0.2.0/24 \
--availability-zone us-east-1b \
--tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=casebender-public-1b}]'
```
### Set Up RDS (PostgreSQL)
```bash theme={null}
# Create DB subnet group
aws rds create-db-subnet-group \
--db-subnet-group-name casebender-db-subnet \
--db-subnet-group-description "Subnet group for CaseBender RDS" \
--subnet-ids "" ""
# Create RDS instance
aws rds create-db-instance \
--db-instance-identifier casebender-db \
--db-instance-class db.t3.medium \
--engine postgres \
--master-username superadmin \
--master-user-password \
--allocated-storage 20 \
--db-subnet-group-name casebender-db-subnet
```
### Set Up ElastiCache (Redis)
```bash theme={null}
# Create cache subnet group
aws elasticache create-cache-subnet-group \
--cache-subnet-group-name casebender-cache-subnet \
--cache-subnet-group-description "Subnet group for CaseBender Redis" \
--subnet-ids "" ""
# Create Redis cluster
aws elasticache create-cache-cluster \
--cache-cluster-id casebender-redis \
--engine redis \
--cache-node-type cache.t3.micro \
--num-cache-nodes 1 \
--cache-subnet-group-name casebender-cache-subnet
```
## Step 3: Create ECR Repositories
```bash theme={null}
# Create repositories for each service
aws ecr create-repository --repository-name casebender/app
aws ecr create-repository --repository-name casebender/workflow-processor
aws ecr create-repository --repository-name casebender/misp-processor
# Get the AWS account ID
AWS_ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text)
# Pull CaseBender images
docker pull casebender/casebender:latest
docker pull casebender/workflow-processor:latest
docker pull casebender/misp-processor:latest
# Tag images for ECR
docker tag casebender/casebender:latest ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/app:latest
docker tag casebender/workflow-processor:latest ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/workflow-processor:latest
docker tag casebender/misp-processor:latest ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/misp-processor:latest
# Push images to ECR
docker push ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/app:latest
docker push ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/workflow-processor:latest
docker push ${AWS_ACCOUNT_ID}.dkr.ecr.us-east-1.amazonaws.com/casebender/misp-processor:latest
```
## Step 4: Create ECS Cluster
```bash theme={null}
# Create ECS cluster
aws ecs create-cluster --cluster-name casebender-cluster
# Create task execution role
aws iam create-role \
--role-name ecsTaskExecutionRole \
--assume-role-policy-document file://task-execution-assume-role.json
# Attach policy
aws iam attach-role-policy \
--role-name ecsTaskExecutionRole \
--policy-arn arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy
```
## Step 5: Create Task Definitions
Create task definition JSON files for each service:
```json theme={null}
{
"family": "casebender-app",
"networkMode": "awsvpc",
"requiresCompatibilities": ["FARGATE"],
"cpu": "1024",
"memory": "2048",
"executionRoleArn": "arn:aws:iam:::role/ecsTaskExecutionRole",
"containerDefinitions": [
{
"name": "app",
"image": ".dkr.ecr.us-east-1.amazonaws.com/casebender/app:latest",
"portMappings": [
{
"containerPort": 3000,
"protocol": "tcp"
}
],
"environment": [
{
"name": "POSTGRES_PRISMA_URL",
"value": "postgresql://superadmin:password@casebender-db.xxxxx.region.rds.amazonaws.com:5432/casebender"
},
{
"name": "REDIS_URL",
"value": "redis://casebender-redis.xxxxx.region.cache.amazonaws.com:6379"
},
{
"name": "AWS_S3_BUCKET",
"value": "casebender-storage"
},
{
"name": "AWS_S3_REGION",
"value": "us-east-1"
}
],
"secrets": [
{
"name": "AUTH_SECRET",
"valueFrom": "arn:aws:secretsmanager:region:account:secret:auth-secret"
},
{
"name": "AUTH_SALT",
"valueFrom": "arn:aws:secretsmanager:region:account:secret:auth-salt"
}
],
"logConfiguration": {
"logDriver": "awslogs",
"options": {
"awslogs-group": "/ecs/casebender",
"awslogs-region": "us-east-1",
"awslogs-stream-prefix": "app"
}
}
}
]
}
```
Register the task definitions:
```bash theme={null}
# Register task definitions
aws ecs register-task-definition --cli-input-json file://app-task-definition.json
aws ecs register-task-definition --cli-input-json file://workflow-processor-task-definition.json
aws ecs register-task-definition --cli-input-json file://misp-processor-task-definition.json
```
## Step 6: Create Application Load Balancer
```bash theme={null}
# Create ALB
aws elbv2 create-load-balancer \
--name casebender-alb \
--subnets \
--security-groups
# Create target group
aws elbv2 create-target-group \
--name casebender-tg \
--protocol HTTP \
--port 3000 \
--vpc-id \
--target-type ip
# Create listener
aws elbv2 create-listener \
--load-balancer-arn \
--protocol HTTPS \
--port 443 \
--certificates CertificateArn= \
--default-actions Type=forward,TargetGroupArn=
```
## Step 7: Create ECS Services
```bash theme={null}
# Create service for main app
aws ecs create-service \
--cluster casebender-cluster \
--service-name casebender-app \
--task-definition casebender-app \
--desired-count 2 \
--launch-type FARGATE \
--network-configuration "awsvpcConfiguration={subnets=[,],securityGroups=[],assignPublicIp=ENABLED}" \
--load-balancers "targetGroupArn=,containerName=app,containerPort=3000"
# Create services for processors
aws ecs create-service \
--cluster casebender-cluster \
--service-name workflow-processor \
--task-definition casebender-workflow-processor \
--desired-count 1 \
--launch-type FARGATE \
--network-configuration "awsvpcConfiguration={subnets=[,],securityGroups=[],assignPublicIp=ENABLED}"
aws ecs create-service \
--cluster casebender-cluster \
--service-name misp-processor \
--task-definition casebender-misp-processor \
--desired-count 1 \
--launch-type FARGATE \
--network-configuration "awsvpcConfiguration={subnets=[,],securityGroups=[],assignPublicIp=ENABLED}"
```
## Step 8: Set Up Route 53 (Optional)
If you're using a custom domain:
```bash theme={null}
# Create hosted zone (if not exists)
aws route53 create-hosted-zone \
--name yourdomain.com \
--caller-reference $(date +%s)
# Create A record
aws route53 change-resource-record-sets \
--hosted-zone-id \
--change-batch '{
"Changes": [{
"Action": "CREATE",
"ResourceRecordSet": {
"Name": "yourdomain.com",
"Type": "A",
"AliasTarget": {
"HostedZoneId": "",
"DNSName": "",
"EvaluateTargetHealth": true
}
}
}]
}'
```
## Monitoring and Maintenance
### Set Up CloudWatch Alarms
```bash theme={null}
# Create CPU utilization alarm
aws cloudwatch put-metric-alarm \
--alarm-name casebender-cpu-alarm \
--alarm-description "CPU utilization exceeded 80%" \
--metric-name CPUUtilization \
--namespace AWS/ECS \
--statistic Average \
--period 300 \
--threshold 80 \
--comparison-operator GreaterThanThreshold \
--dimensions Name=ClusterName,Value=casebender-cluster \
--evaluation-periods 2 \
--alarm-actions
```
### View Logs
```bash theme={null}
# View service logs
aws logs get-log-events \
--log-group-name /ecs/casebender \
--log-stream-name app/
```
### Update Services
```bash theme={null}
# Update service with new task definition
aws ecs update-service \
--cluster casebender-cluster \
--service casebender-app \
--task-definition casebender-app:NEW_REVISION
```
## Cost Optimization
1. Use Fargate Spot for non-critical workloads
2. Implement auto-scaling based on metrics
3. Choose appropriate instance sizes
4. Use Reserved Instances for predictable workloads
## Security Best Practices
1. Use AWS Secrets Manager for sensitive data
2. Implement WAF rules
3. Enable VPC Flow Logs
4. Regular security group audits
5. Enable AWS GuardDuty
## Next Steps
* Set up CI/CD pipeline with AWS CodePipeline
* Configure backup strategies
* Implement monitoring and alerting
* Review security best practices
# Deploy to Azure
Source: https://docs.casebender.com/en/deployment/azure
Deploy CaseBender on Microsoft Azure
## Overview
This guide walks you through deploying CaseBender on Azure using pre-built Docker images with Azure Container Apps and managed services.
## Prerequisites
1. [Azure Account](https://azure.microsoft.com/)
2. [Azure CLI](https://docs.microsoft.com/en-us/cli/azure/install-azure-cli) installed
3. [Docker](https://docs.docker.com/get-docker/) installed
## Step 1: Initial Setup
### Install and Configure Azure CLI
```bash macOS theme={null}
# Using Homebrew
brew install azure-cli
# Login to Azure
az login
# Configure Docker for ACR
az acr login --name casebenderacr
```
```bash Linux theme={null}
# Install Azure CLI
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
# Login to Azure
az login
# Configure Docker for ACR
az acr login --name casebenderacr
```
```powershell Windows theme={null}
# Using winget
winget install -e --id Microsoft.AzureCLI
# Login to Azure
az login
# Configure Docker for ACR
az acr login --name casebenderacr
```
### Initialize Project
```bash theme={null}
# Set variables
RESOURCE_GROUP="casebender-rg"
LOCATION="eastus"
# Create resource group
az group create --name $RESOURCE_GROUP --location $LOCATION
# Enable required services
az provider register --namespace Microsoft.ContainerRegistry
az provider register --namespace Microsoft.App
az provider register --namespace Microsoft.Storage
```
## Step 2: Set Up Azure Infrastructure
### Create Storage Account
```bash theme={null}
# Create storage account
az storage account create \
--name casebenderstorage \
--resource-group $RESOURCE_GROUP \
--location $LOCATION \
--sku Standard_LRS \
--encryption-services blob
# Create blob container
az storage container create \
--name casebender \
--account-name casebenderstorage \
--auth-mode key \
--public-access off
# Get storage account key
STORAGE_KEY=$(az storage account keys list \
--account-name casebenderstorage \
--resource-group $RESOURCE_GROUP \
--query '[0].value' -o tsv)
# Create managed identity for storage access
az identity create \
--name casebender-storage-identity \
--resource-group $RESOURCE_GROUP
# Get managed identity ID
IDENTITY_ID=$(az identity show \
--name casebender-storage-identity \
--resource-group $RESOURCE_GROUP \
--query id -o tsv)
# Assign Storage Blob Data Contributor role
az role assignment create \
--assignee-object-id $(az identity show --name casebender-storage-identity --resource-group $RESOURCE_GROUP --query principalId -o tsv) \
--role "Storage Blob Data Contributor" \
--scope $(az storage account show --name casebenderstorage --resource-group $RESOURCE_GROUP --query id -o tsv)
```
### Set Up Azure Database for PostgreSQL
```bash theme={null}
# Create PostgreSQL server
az postgres flexible-server create \
--resource-group $RESOURCE_GROUP \
--name casebender-db \
--admin-user superadmin \
--admin-password \
--sku-name Standard_B2s \
--storage-size 32 \
--version 14
# Create database
az postgres flexible-server db create \
--resource-group $RESOURCE_GROUP \
--server-name casebender-db \
--database-name casebender
```
### Set Up Azure Cache for Redis
```bash theme={null}
# Create Redis cache
az redis create \
--resource-group $RESOURCE_GROUP \
--name casebender-redis \
--sku Basic \
--vm-size c0 \
--location $LOCATION
```
## Step 3: Create and Configure Container Registry
```bash theme={null}
# Create Azure Container Registry
az acr create \
--resource-group $RESOURCE_GROUP \
--name casebenderacr \
--sku Standard \
--admin-enabled true
# Get registry credentials
ACR_USERNAME=$(az acr credential show --name casebenderacr --query username -o tsv)
ACR_PASSWORD=$(az acr credential show --name casebenderacr --query "passwords[0].value" -o tsv)
# Pull CaseBender images
docker pull casebender/casebender:latest
docker pull casebender/workflow-processor:latest
docker pull casebender/misp-processor:latest
# Tag images for ACR
docker tag casebender/casebender:latest casebenderacr.azurecr.io/casebender/app:latest
docker tag casebender/workflow-processor:latest casebenderacr.azurecr.io/casebender/workflow-processor:latest
docker tag casebender/misp-processor:latest casebenderacr.azurecr.io/casebender/misp-processor:latest
# Push images to ACR
docker push casebenderacr.azurecr.io/casebender/app:latest
docker push casebenderacr.azurecr.io/casebender/workflow-processor:latest
docker push casebenderacr.azurecr.io/casebender/misp-processor:latest
```
## Step 4: Deploy Services
### Create Container Apps Environment
```bash theme={null}
# Create Container Apps environment
az containerapp env create \
--name casebender-env \
--resource-group $RESOURCE_GROUP \
--location $LOCATION
# Create main application
az containerapp create \
--name casebender-app \
--resource-group $RESOURCE_GROUP \
--environment casebender-env \
--image casebenderacr.azurecr.io/casebender/app:latest \
--target-port 3000 \
--ingress external \
--registry-server casebenderacr.azurecr.io \
--registry-username $ACR_USERNAME \
--registry-password $ACR_PASSWORD \
--user-assigned-identity $IDENTITY_ID \
--env-vars \
AUTH_SECRET= \
AUTH_SALT= \
POSTGRES_PRISMA_URL="postgresql://superadmin:@casebender-db.postgres.database.azure.com:5432/casebender" \
REDIS_URL="redis://casebender-redis.redis.cache.windows.net:6380?ssl=true&password=" \
AZURE_STORAGE_ACCOUNT="casebenderstorage" \
AZURE_STORAGE_CONTAINER="casebender" \
AZURE_STORAGE_CONNECTION_STRING="DefaultEndpointsProtocol=https;AccountName=casebenderstorage;AccountKey=${STORAGE_KEY};EndpointSuffix=core.windows.net"
# Create workflow processor
az containerapp create \
--name workflow-processor \
--resource-group $RESOURCE_GROUP \
--environment casebender-env \
--image casebenderacr.azurecr.io/casebender/workflow-processor:latest \
--registry-server casebenderacr.azurecr.io \
--registry-username $ACR_USERNAME \
--registry-password $ACR_PASSWORD \
--min-replicas 1 \
--max-replicas 1 \
--env-vars \
POSTGRES_PRISMA_URL="postgresql://superadmin:@casebender-db.postgres.database.azure.com:5432/casebender" \
REDIS_URL="redis://casebender-redis.redis.cache.windows.net:6380?ssl=true&password="
# Create MISP processor
az containerapp create \
--name misp-processor \
--resource-group $RESOURCE_GROUP \
--environment casebender-env \
--image casebenderacr.azurecr.io/casebender/misp-processor:latest \
--registry-server casebenderacr.azurecr.io \
--registry-username $ACR_USERNAME \
--registry-password $ACR_PASSWORD \
--min-replicas 1 \
--max-replicas 1 \
--env-vars \
POSTGRES_PRISMA_URL="postgresql://superadmin:@casebender-db.postgres.database.azure.com:5432/casebender" \
REDIS_URL="redis://casebender-redis.redis.cache.windows.net:6380?ssl=true&password="
```
## Step 5: Set Up Azure Front Door
```bash theme={null}
# Create Front Door profile
az afd profile create \
--profile-name casebender-afd \
--resource-group $RESOURCE_GROUP \
--sku Standard_AzureFrontDoor
# Create endpoint
az afd endpoint create \
--endpoint-name casebender \
--profile-name casebender-afd \
--resource-group $RESOURCE_GROUP
# Create origin group
az afd origin-group create \
--origin-group-name casebender-origin-group \
--profile-name casebender-afd \
--resource-group $RESOURCE_GROUP \
--probe-path "/" \
--probe-protocol Http \
--probe-request-type GET
# Add origin
az afd origin create \
--origin-group-name casebender-origin-group \
--origin-name casebender-origin \
--profile-name casebender-afd \
--resource-group $RESOURCE_GROUP \
--host-name \
--origin-host-header \
--priority 1 \
--weight 1000 \
--enabled-state Enabled
```
## Step 6: Configure Custom Domain (Optional)
```bash theme={null}
# Add custom domain to Front Door
az afd custom-domain create \
--custom-domain-name casebender-domain \
--host-name your-domain.com \
--profile-name casebender-afd \
--resource-group $RESOURCE_GROUP \
--minimum-tls-version TLS12
# Enable HTTPS
az afd custom-domain enable-https \
--custom-domain-name casebender-domain \
--profile-name casebender-afd \
--resource-group $RESOURCE_GROUP
```
## Monitoring and Maintenance
### Set Up Application Insights
```bash theme={null}
# Create Application Insights
az monitor app-insights component create \
--app casebender-insights \
--location $LOCATION \
--resource-group $RESOURCE_GROUP \
--application-type web
# Get instrumentation key
az monitor app-insights component show \
--app casebender-insights \
--resource-group $RESOURCE_GROUP \
--query instrumentationKey \
--output tsv
```
### Configure Alerts
```bash theme={null}
# Create action group
az monitor action-group create \
--name casebender-alerts \
--resource-group $RESOURCE_GROUP \
--action email admin email@yourdomain.com
# Create alert rule
az monitor metrics alert create \
--name "high-cpu-usage" \
--resource-group $RESOURCE_GROUP \
--scopes \
--condition "avg CPU > 80" \
--window-size 5m \
--evaluation-frequency 1m \
--action
```
### View Logs
```bash theme={null}
# View container app logs
az containerapp logs show \
--name casebender-app \
--resource-group $RESOURCE_GROUP \
--follow
```
## Scaling Configuration
```bash theme={null}
# Configure scaling rules
az containerapp update \
--name casebender-app \
--resource-group $RESOURCE_GROUP \
--min-replicas 1 \
--max-replicas 10 \
--scale-rule-name http-rule \
--scale-rule-type http \
--scale-rule-http-concurrency 50
```
## Backup and Disaster Recovery
### Configure Database Backups
```bash theme={null}
# Enable automated backups
az postgres flexible-server update \
--resource-group $RESOURCE_GROUP \
--name casebender-db \
--backup-retention 7
```
### Configure Geo-Replication
```bash theme={null}
# Create secondary region resources
az postgres flexible-server replica create \
--name casebender-db-secondary \
--source-server casebender-db \
--resource-group $RESOURCE_GROUP \
--location westus
```
## Security Best Practices
1. Enable Azure Defender for all services
2. Implement Azure Private Link
3. Use Managed Identities
4. Regular security assessments
5. Enable diagnostic logging
## Cost Optimization
1. Use consumption plan for Container Apps
2. Implement auto-scaling rules
3. Choose appropriate service tiers
4. Monitor usage patterns
5. Use Azure Reserved Instances
## Next Steps
* Set up CI/CD with Azure DevOps
* Implement comprehensive monitoring
* Configure disaster recovery
* Review security compliance
# Desktop Installer
Source: https://docs.casebender.com/en/deployment/desktop-installer
One-click installer for deploying CaseBender locally
The CaseBender Desktop Installer is the easiest way to deploy CaseBender on your local machine. It handles Docker setup, configuration, and service management automatically.
## Download Installer
The installer automatically detects your system and configures CaseBender with optimal settings.
**For Apple Silicon (M1/M2/M3) and Intel Macs**
Recommended for M1/M2/M3 Macs
For Intel-based Macs
**Installation:**
1. Download the DMG file for your Mac
2. Open the DMG and drag CaseBender Installer to Applications
3. Launch from Applications folder
4. If prompted about unidentified developer, right-click and select "Open"
**For Windows 10/11 (64-bit)**
Recommended installer with auto-updates
No installation required
**Installation:**
1. Download the installer
2. Run the installer (you may need to click "More info" → "Run anyway" if Windows SmartScreen appears)
3. Follow the installation wizard
4. Launch CaseBender Installer from the Start menu
**For Ubuntu, Debian, and other distributions**
Works on most Linux distributions
For Debian/Ubuntu-based systems
**Installation (AppImage):**
```bash theme={null}
chmod +x CaseBender-Installer.AppImage
./CaseBender-Installer.AppImage
```
**Installation (DEB):**
```bash theme={null}
sudo dpkg -i CaseBender-Installer.deb
sudo apt-get install -f # Install dependencies if needed
```
## System Requirements
| Component | Minimum | Recommended |
| -------------- | ---------------------------------------- | ----------- |
| **RAM** | 8 GB | 16 GB |
| **Disk Space** | 10 GB | 20 GB |
| **Docker** | 20.10+ | Latest |
| **OS** | macOS 10.15+, Windows 10+, Ubuntu 20.04+ | Latest LTS |
Docker Desktop must be installed and running before using the CaseBender Installer. The installer will guide you through Docker installation if it's not detected.
## Features
Deploy CaseBender with a single click. No command line required.
Automatically generates secure credentials and SSL certificates.
Start, stop, and monitor all CaseBender services from a unified dashboard.
Update to the latest version with one click.
## What Gets Installed
The installer deploys the following services:
* **CaseBender Web App** - Main application (port 3000)
* **PostgreSQL** - Database (port 5433)
* **Redis** - Cache and message queue (port 6379)
* **Workflow Processor** - Background job processing (port 3001)
* **MISP Processor** - Threat intelligence integration (port 3002)
* **MinIO** - Object storage for attachments (ports 9000, 9090)
* **Nginx** - SSL termination and reverse proxy (ports 80, 443)
## First Launch
After installation:
1. **Start Docker Desktop** - Ensure Docker is running
2. **Launch the Installer** - Open CaseBender Installer
3. **Click "Install"** - The installer will pull images and configure services
4. **Access CaseBender** - Open `https://local.casebender.com` in your browser
## Default Credentials
```
Username: admin@casebender.app
Password: secret1234
```
Change these credentials immediately after your first login for security.
## Troubleshooting
### Docker Not Found
If the installer can't find Docker:
1. Install [Docker Desktop](https://www.docker.com/products/docker-desktop/)
2. Start Docker Desktop
3. Wait for Docker to fully initialize (green icon in system tray)
4. Restart the CaseBender Installer
### Port Conflicts
If you see port conflict errors:
1. Check which application is using the port: `lsof -i :PORT` (macOS/Linux) or `netstat -ano | findstr :PORT` (Windows)
2. Stop the conflicting application
3. Retry the installation
### macOS Gatekeeper Warning
If macOS blocks the app:
1. Right-click (or Control+click) on the app
2. Select "Open" from the context menu
3. Click "Open" in the dialog
### Windows SmartScreen
If Windows blocks the installer:
1. Click "More info"
2. Click "Run anyway"
## Manual Installation
If you prefer manual installation or need more control, see the [Quickstart Guide](/en/quickstart) for Docker Compose setup instructions.
## All Releases
View all available versions and release notes on our [GitHub Releases](https://github.com/casebender/casebender/releases) page.
# Deploy to DigitalOcean
Source: https://docs.casebender.com/en/deployment/digitalocean
Deploy CaseBender on DigitalOcean
## Overview
This guide walks you through deploying CaseBender on DigitalOcean using pre-built Docker images with Kubernetes (DOKS) and managed services.
## Prerequisites
1. [DigitalOcean Account](https://cloud.digitalocean.com/)
2. [doctl](https://docs.digitalocean.com/reference/doctl/how-to/install/) CLI installed
3. [kubectl](https://kubernetes.io/docs/tasks/tools/) installed
4. [Docker](https://docs.docker.com/get-docker/) installed
## Step 1: Initial Setup
### Install and Configure doctl
```bash macOS theme={null}
# Using Homebrew
brew install doctl
# Authenticate with API token
doctl auth init
# Configure Docker for Container Registry
doctl registry login
```
```bash Linux theme={null}
# Download latest release
cd ~/Downloads
wget https://github.com/digitalocean/doctl/releases/download/v1.XX.X/doctl-1.XX.X-linux-amd64.tar.gz
# Extract and move to path
tar xf ~/Downloads/doctl-1.XX.X-linux-amd64.tar.gz
sudo mv ~/Downloads/doctl /usr/local/bin
# Authenticate with API token
doctl auth init
# Configure Docker for Container Registry
doctl registry login
```
```powershell Windows theme={null}
# Using Chocolatey
choco install doctl
# Authenticate with API token
doctl auth init
# Configure Docker for Container Registry
doctl registry login
```
## Step 2: Create Kubernetes Cluster
```bash theme={null}
# Create DOKS cluster
doctl kubernetes cluster create casebender \
--region nyc1 \
--size s-2vcpu-4gb \
--count 3 \
--version latest
# Get kubeconfig
doctl kubernetes cluster kubeconfig save casebender
```
## Step 3: Set Up Managed Services
### Create Spaces for Object Storage
```bash theme={null}
# Create Spaces bucket
doctl spaces create casebender-storage \
--region nyc3
# Create Spaces access key
doctl spaces access-key create
# Note: Save the access key and secret key securely
# They will be needed for application configuration
```
### Create Managed PostgreSQL
```bash theme={null}
# Create database cluster
doctl databases create \
--engine pg \
--name casebender-db \
--region nyc1 \
--size db-s-2vcpu-4gb \
--version 14 \
--num-nodes 1
# Create database
doctl databases db create casebender-db casebender
# Get connection details
doctl databases connection casebender-db --format ConnectionString
```
### Create Managed Redis
```bash theme={null}
# Create Redis cluster
doctl databases create \
--engine redis \
--name casebender-redis \
--region nyc1 \
--size db-s-1vcpu-2gb \
--version 7
# Get connection details
doctl databases connection casebender-redis --format ConnectionString
```
## Step 4: Configure Container Registry
```bash theme={null}
# Create container registry
doctl registry create casebender-registry
# Get registry endpoint
REGISTRY_ENDPOINT=$(doctl registry get-endpoint)
# Pull CaseBender images
docker pull casebender/casebender:latest
docker pull casebender/workflow-processor:latest
docker pull casebender/misp-processor:latest
# Tag images for registry
docker tag casebender/casebender:latest registry.digitalocean.com/casebender-registry/app:latest
docker tag casebender/workflow-processor:latest registry.digitalocean.com/casebender-registry/workflow-processor:latest
docker tag casebender/misp-processor:latest registry.digitalocean.com/casebender-registry/misp-processor:latest
# Push images
docker push registry.digitalocean.com/casebender-registry/app:latest
docker push registry.digitalocean.com/casebender-registry/workflow-processor:latest
docker push registry.digitalocean.com/casebender-registry/misp-processor:latest
# Add registry to Kubernetes cluster
doctl kubernetes cluster registry add casebender
```
## Step 5: Deploy to Kubernetes
### Create Namespace
```bash theme={null}
kubectl create namespace casebender
```
### Create Secrets
```bash theme={null}
# Create secrets for database and Redis
kubectl create secret generic db-credentials \
--namespace casebender \
--from-literal=postgres-url="postgresql://doadmin:password@casebender-db-do-user-1234567-0.b.db.ondigitalocean.com:25060/casebender?sslmode=require" \
--from-literal=redis-url="rediss://default:password@casebender-redis-do-user-1234567-0.b.db.ondigitalocean.com:25061"
# Create secrets for application
kubectl create secret generic app-secrets \
--namespace casebender \
--from-literal=auth-secret="your-auth-secret" \
--from-literal=auth-salt="your-auth-salt"
```
### Deploy Applications
Create `deployment.yaml`:
```yaml theme={null}
apiVersion: apps/v1
kind: Deployment
metadata:
name: casebender-app
namespace: casebender
spec:
replicas: 2
selector:
matchLabels:
app: casebender-app
template:
metadata:
labels:
app: casebender-app
spec:
containers:
- name: app
image: registry.digitalocean.com/casebender-registry/app:latest
ports:
- containerPort: 3000
env:
- name: AUTH_SECRET
valueFrom:
secretKeyRef:
name: app-secrets
key: auth-secret
- name: AUTH_SALT
valueFrom:
secretKeyRef:
name: app-secrets
key: auth-salt
- name: POSTGRES_PRISMA_URL
valueFrom:
secretKeyRef:
name: db-credentials
key: postgres-url
- name: REDIS_URL
valueFrom:
secretKeyRef:
name: db-credentials
key: redis-url
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: workflow-processor
namespace: casebender
spec:
replicas: 1
selector:
matchLabels:
app: workflow-processor
template:
metadata:
labels:
app: workflow-processor
spec:
containers:
- name: processor
image: registry.digitalocean.com/casebender-registry/workflow-processor:latest
env:
- name: POSTGRES_PRISMA_URL
valueFrom:
secretKeyRef:
name: db-credentials
key: postgres-url
- name: REDIS_URL
valueFrom:
secretKeyRef:
name: db-credentials
key: redis-url
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: misp-processor
namespace: casebender
spec:
replicas: 1
selector:
matchLabels:
app: misp-processor
template:
metadata:
labels:
app: misp-processor
spec:
containers:
- name: processor
image: registry.digitalocean.com/casebender-registry/misp-processor:latest
env:
- name: POSTGRES_PRISMA_URL
valueFrom:
secretKeyRef:
name: db-credentials
key: postgres-url
- name: REDIS_URL
valueFrom:
secretKeyRef:
name: db-credentials
key: redis-url
```
Apply the deployments:
```bash theme={null}
kubectl apply -f deployment.yaml
```
### Create Services
Create `service.yaml`:
```yaml theme={null}
apiVersion: v1
kind: Service
metadata:
name: casebender-app
namespace: casebender
spec:
type: ClusterIP
ports:
- port: 80
targetPort: 3000
selector:
app: casebender-app
```
Apply the service:
```bash theme={null}
kubectl apply -f service.yaml
```
## Step 7: Set Up Ingress
### Install NGINX Ingress Controller
```bash theme={null}
# Add Helm repository
helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
helm repo update
# Install NGINX Ingress Controller
helm install nginx-ingress ingress-nginx/ingress-nginx \
--namespace casebender \
--set controller.publishService.enabled=true
```
### Configure Ingress
Create `ingress.yaml`:
```yaml theme={null}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: casebender-ingress
namespace: casebender
annotations:
kubernetes.io/ingress.class: nginx
cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
tls:
- hosts:
- your-domain.com
secretName: casebender-tls
rules:
- host: your-domain.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: casebender-app
port:
number: 80
```
Apply the ingress:
```bash theme={null}
kubectl apply -f ingress.yaml
```
## Step 8: Set Up SSL with cert-manager
```bash theme={null}
# Install cert-manager
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.8.0/cert-manager.yaml
# Create ClusterIssuer
cat <
```bash macOS theme={null}
# Using Homebrew
brew install google-cloud-sdk
# Login to Google Cloud
gcloud auth login
# Configure Docker to use Google Cloud
gcloud auth configure-docker
```
```bash Linux theme={null}
# Download the archive
curl -O https://dl.google.com/dl/cloudsdk/channels/rapid/downloads/google-cloud-cli-VERSION-linux-x86_64.tar.gz
# Extract the archive
tar -xf google-cloud-cli-VERSION-linux-x86_64.tar.gz
# Run the install script
./google-cloud-sdk/install.sh
# Login to Google Cloud
gcloud auth login
# Configure Docker to use Google Cloud
gcloud auth configure-docker
```
```powershell Windows theme={null}
# Download and run the installer
# https://dl.google.com/dl/cloudsdk/channels/rapid/GoogleCloudSDKInstaller.exe
# Login to Google Cloud
gcloud auth login
# Configure Docker to use Google Cloud
gcloud auth configure-docker
```
### Initialize Project
```bash theme={null}
# Set your project ID
gcloud config set project YOUR_PROJECT_ID
# Enable required APIs
gcloud services enable \
cloudbuild.googleapis.com \
run.googleapis.com \
secretmanager.googleapis.com \
cloudresourcemanager.googleapis.com \
artifactregistry.googleapis.com
```
## Step 2: Set Up Cloud Infrastructure
### Create Cloud Storage Bucket
```bash theme={null}
# Create storage bucket
gsutil mb -l us-central1 gs://casebender-storage
# Create service account for storage
gcloud iam service-accounts create casebender-storage \
--display-name "CaseBender Storage Service Account"
# Get the service account email
STORAGE_SA_EMAIL=$(gcloud iam service-accounts list \
--filter="displayName:CaseBender Storage Service Account" \
--format="value(email)")
# Grant permissions
gsutil iam ch \
serviceAccount:$STORAGE_SA_EMAIL:objectViewer,objectCreator \
gs://casebender-storage
# Create and download service account key
gcloud iam service-accounts keys create storage-key.json \
--iam-account=$STORAGE_SA_EMAIL
# Create secret for storage credentials
gcloud secrets create casebender-storage-key \
--replication-policy="automatic"
# Import the service account key as a secret
gcloud secrets versions add casebender-storage-key \
--data-file=storage-key.json
```
### Set Up Cloud SQL (PostgreSQL)
```bash theme={null}
# Create PostgreSQL instance
gcloud sql instances create casebender-db \
--database-version=POSTGRES_14 \
--cpu=2 \
--memory=4GB \
--region=us-central1 \
--root-password="YOUR_SECURE_PASSWORD"
# Create database
gcloud sql databases create casebender \
--instance=casebender-db
# Create user
gcloud sql users create casebender \
--instance=casebender-db \
--password="YOUR_SECURE_PASSWORD"
```
### Set Up Memorystore (Redis)
```bash theme={null}
# Create Redis instance
gcloud redis instances create casebender-redis \
--size=2 \
--region=us-central1 \
--redis-version=redis_6_x
```
### Configure Secret Manager
```bash theme={null}
# Create and store environment variables
cat << EOF | gcloud secrets create casebender-env --data-file=-
AUTH_SECRET=your-auth-secret
AUTH_SALT=your-auth-salt
POSTGRES_PRISMA_URL="postgresql://casebender:YOUR_SECURE_PASSWORD@/casebender?host=/cloudsql/YOUR_PROJECT_ID:us-central1:casebender-db"
REDIS_URL="redis://REDIS_IP_ADDRESS:6379"
GOOGLE_STORAGE_BUCKET=casebender-storage
EOF
```
## Step 3: Pull and Push Docker Images
```bash theme={null}
# Create Artifact Registry repository
gcloud artifacts repositories create casebender \
--repository-format=docker \
--location=us-central1
# Configure Docker for Artifact Registry
gcloud auth configure-docker us-central1-docker.pkg.dev
# Pull CaseBender images
docker pull casebender/casebender:latest
docker pull casebender/workflow-processor:latest
docker pull casebender/misp-processor:latest
# Tag images for Google Artifact Registry
docker tag casebender/casebender:latest us-central1-docker.pkg.dev/$PROJECT_ID/casebender/app:latest
docker tag casebender/workflow-processor:latest us-central1-docker.pkg.dev/$PROJECT_ID/casebender/workflow-processor:latest
docker tag casebender/misp-processor:latest us-central1-docker.pkg.dev/$PROJECT_ID/casebender/misp-processor:latest
# Push images
docker push us-central1-docker.pkg.dev/$PROJECT_ID/casebender/app:latest
docker push us-central1-docker.pkg.dev/$PROJECT_ID/casebender/workflow-processor:latest
docker push us-central1-docker.pkg.dev/$PROJECT_ID/casebender/misp-processor:latest
```
## Step 4: Deploy Services
### Deploy Main Application
```bash theme={null}
# Deploy to Cloud Run
gcloud run deploy casebender \
--image us-central1-docker.pkg.dev/$PROJECT_ID/casebender/app:latest \
--platform managed \
--region us-central1 \
--allow-unauthenticated \
--set-env-vars GOOGLE_STORAGE_BUCKET=casebender-storage \
--set-secrets "/secrets/storage-key=casebender-storage-key:latest" \
--service-account=$STORAGE_SA_EMAIL \
--add-cloudsql-instances $PROJECT_ID:us-central1:casebender-db \
--set-secrets "/app/.env=casebender-env:latest"
```
### Deploy Workflow Processor
```bash theme={null}
# Deploy workflow processor
gcloud run deploy workflow-processor \
--image us-central1-docker.pkg.dev/$PROJECT_ID/casebender/workflow-processor:latest \
--platform managed \
--region us-central1 \
--no-allow-unauthenticated \
--service-account=$STORAGE_SA_EMAIL \
--add-cloudsql-instances $PROJECT_ID:us-central1:casebender-db \
--set-secrets "/app/.env=casebender-env:latest"
```
### Deploy MISP Processor
```bash theme={null}
# Deploy MISP processor
gcloud run deploy misp-processor \
--image us-central1-docker.pkg.dev/$PROJECT_ID/casebender/misp-processor:latest \
--platform managed \
--region us-central1 \
--no-allow-unauthenticated \
--service-account=$STORAGE_SA_EMAIL \
--add-cloudsql-instances $PROJECT_ID:us-central1:casebender-db \
--set-secrets "/app/.env=casebender-env:latest"
```
## Step 5: Configure Domain and SSL
### Map Custom Domain
```bash theme={null}
# Add domain mapping
gcloud run domain-mappings create \
--service casebender \
--domain your-domain.com \
--region us-central1
```
Follow the DNS verification steps in the Google Cloud Console to complete domain mapping.
## Monitoring and Maintenance
### Set Up Monitoring
1. Navigate to Cloud Monitoring in Google Cloud Console
2. Create an uptime check for your service
3. Set up alerts for:
* Error rates
* Latency
* Instance count
* Memory usage
### View Logs
```bash theme={null}
# View service logs
gcloud logging read "resource.type=cloud_run_revision AND resource.labels.service_name=casebender" --limit 50
# Stream logs
gcloud logging tail "resource.type=cloud_run_revision AND resource.labels.service_name=casebender"
```
### Update Application
To deploy updates:
```bash theme={null}
# Build and deploy new version
gcloud builds submit --config cloudbuild.yaml
# Roll back if needed
gcloud run services rollback casebender \
--to-revision=REVISION_ID \
--region=us-central1
```
## Cost Optimization
1. **Autoscaling Configuration**
```bash theme={null}
gcloud run services update casebender \
--min-instances=1 \
--max-instances=10 \
--region=us-central1
```
2. **Resource Allocation**
```bash theme={null}
gcloud run services update casebender \
--memory=1Gi \
--cpu=1 \
--region=us-central1
```
## Troubleshooting
### Common Issues
1. **Connection Issues**
* Verify Cloud SQL connection
* Check Redis connectivity
* Validate environment variables
2. **Performance Problems**
* Review instance metrics
* Check resource allocation
* Analyze request patterns
3. **Deployment Failures**
* Check build logs
* Verify service account permissions
* Review deployment configuration
## Next Steps
* Set up CI/CD pipelines
* Configure backup strategies
* Implement monitoring and alerting
* Review security best practices
# Deployment Overview
Source: https://docs.casebender.com/en/deployment/overview
Learn how to deploy CaseBender to various cloud platforms
## Deployment Options
CaseBender can be deployed to various cloud platforms, each offering different advantages. Choose the platform that best suits your organization's needs:
Serverless container platform with automatic scaling
Deploy on Amazon's cloud infrastructure
Microsoft's cloud platform with enterprise features
Simple and cost-effective cloud platform
## Deployment Considerations
Before deploying CaseBender to production, consider the following:
### Infrastructure Requirements
* **CPU/Memory**: Minimum 2 vCPUs and 4GB RAM recommended
* **Storage**: At least 20GB for the application and databases
* **Network**: HTTPS required, with valid SSL certificate
* **Database**: PostgreSQL 14+ instance
* **Cache**: Redis 6+ instance
### Security Considerations
1. **SSL/TLS Configuration**
* Always use HTTPS in production
* Keep certificates up to date
* Configure secure SSL parameters
2. **Network Security**
* Set up proper firewalls
* Use private networking where possible
* Implement rate limiting
3. **Access Control**
* Use strong authentication
* Implement role-based access control
* Regular security audits
### Monitoring and Maintenance
1. **Health Checks**
* Set up application monitoring
* Configure automated health checks
* Implement logging and alerting
2. **Backup Strategy**
* Regular database backups
* Automated backup testing
* Disaster recovery plan
3. **Updates and Maintenance**
* Regular security updates
* Scheduled maintenance windows
* Version control strategy
## Deployment Checklist
Before deploying to any platform, ensure you have:
* [ ] Production-ready SSL certificates
* [ ] Secure environment variables
* [ ] Database backup strategy
* [ ] Monitoring tools configured
* [ ] Security measures implemented
* [ ] Documentation for maintenance procedures
## Next Steps
Choose your preferred deployment platform from the options above to get detailed, platform-specific deployment instructions.
# Introduction
Source: https://docs.casebender.com/en/introduction
Welcome to CaseBender Documentation
## Welcome to CaseBender
CaseBender is a powerful case management and alert handling platform designed to streamline your security operations. Our platform helps teams efficiently manage, investigate, and respond to security alerts and cases.
## Key Features
Efficiently handle and process security alerts with advanced filtering and
automation
Create and manage cases with comprehensive tracking and collaboration
features
Automate repetitive tasks and streamline your security operations
Connect with your existing security tools and data sources
Enterprise-grade security with 20+ controls and 10+ compliance frameworks
## Getting Started
Get started with CaseBender by following our comprehensive guides:
Get up and running with CaseBender in minutes
Learn about the fundamental concepts of CaseBender
# Quickstart Guide
Source: https://docs.casebender.com/en/quickstart
Deploy CaseBender locally in minutes
**Looking for an easier way?** Use our [Desktop Installer](/en/deployment/desktop-installer) for one-click deployment with automatic configuration. No command line required!
## Prerequisites
Before you begin, make sure you have the following installed on your system:
* Docker Engine (20.10.0 or higher)
* Docker Compose (v2.0.0 or higher)
* OpenSSL (for generating SSL certificates)
### Installing Docker
#### For macOS:
1. Download and install Docker Desktop from [Docker Hub](https://hub.docker.com/editions/community/docker-ce-desktop-mac)
2. Follow the installation wizard
3. Verify installation:
```bash theme={null}
docker --version
docker compose --version
```
#### For Linux (Ubuntu/Debian):
```bash theme={null}
# Update package index
sudo apt-get update
# Install prerequisites
sudo apt-get install \
apt-transport-https \
ca-certificates \
curl \
gnupg \
lsb-release
# Add Docker's official GPG key
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
# Set up stable repository
echo \
"deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu \
$(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
# Install Docker Engine
sudo apt-get update
sudo apt-get install docker-ce docker-ce-cli containerd.io docker-compose-plugin
# Add your user to docker group
sudo usermod -aG docker $USER
```
#### For Windows:
1. Download and install Docker Desktop from [Docker Hub](https://hub.docker.com/editions/community/docker-ce-desktop-windows)
2. Enable WSL 2 following Docker's documentation
3. Follow the installation wizard
4. Verify installation in PowerShell:
```powershell theme={null}
docker --version
docker compose --version
```
## Step 1: Create Project Directory
Create a new directory for your CaseBender deployment and navigate into it:
```bash theme={null}
mkdir casebender-deployment
cd casebender-deployment
```
## Step 2: Configure Environment Variables
Create a `.env` file with the following content:
```bash theme={null}
# Authentication
AUTH_SECRET="B7OawnWf6+LwB/9yXbxbk4ppZ1khydqj4qc9k9g3nnE="
AUTH_SALT="B7OawnW"
AUTH_TRUST_HOST=true
NEXTAUTH_URL=https://local.casebender.com
NEXTAPP_URL=https://local.casebender.com
# License
# On first boot the app auto-generates a Community license. Set a stable key so
# your license survives restarts. Generate one with: openssl rand -hex 32
LICENSE_SECRET_KEY=replace-with-output-of-openssl-rand-hex-32
# Liveblocks Configuration (real-time collaboration)
LIVEBLOCKS_SECRET_KEY=sk_dev_HaIczPV4gPit5_gx7YRsNXLGJNzBE5wQ8z8I1H8ft3ZPZHVrfH2ryJJ586ezHYla
# Database Configuration (host is the internal "db" service)
POSTGRES_PASSWORD=88AlwaysTimeToWin88
POSTGRES_PRISMA_URL="postgresql://superadmin:88AlwaysTimeToWin88@db:5432/casebender?schema=public"
POSTGRES_URL="postgresql://superadmin:88AlwaysTimeToWin88@db:5432/casebender?schema=public"
POSTGRES_URL_NON_POOLING="postgresql://superadmin:88AlwaysTimeToWin88@db:5432/casebender?schema=public"
# Redis Configuration
REDIS_URL="redis://redis:6379"
```
CaseBender runs as several containers: the **web app** (`app`), a **REST API gateway**
(`api`), an **alert ingestion gateway** (`ingestion`, this is what receives integration
webhooks such as Microsoft Defender), a background **worker**, and the **workflow** and
**MISP** processors. Nginx sits in front and routes traffic to the right service. All of these
are included in the Compose file below.
## Step 3: Generate SSL Certificates
For local development, generate self-signed SSL certificates:
```bash theme={null}
# Generate SSL certificate and key
openssl req -x509 -nodes -days 365 -newkey rsa:2048 \
-keyout local-casebender.key \
-out local-casebender.crt \
-subj "/CN=local.casebender.com/O=CaseBender/C=US"
# Verify the certificate
openssl x509 -in local-casebender.crt -text -noout
```
## Step 4: Configure Nginx
Create `nginx.conf` with the following content:
```nginx theme={null}
events {
worker_connections 1024;
}
http {
# ─── Upstreams ─────────────────────────────────────────────
upstream web_app {
server app:3000;
}
upstream api_service {
server api:3005;
}
upstream ingestion_service {
server ingestion:3003;
}
# ─── Rate Limiting ─────────────────────────────────────────
limit_req_zone $binary_remote_addr zone=api_limit:10m rate=100r/s;
limit_req_zone $binary_remote_addr zone=ingest_limit:10m rate=1000r/s;
# ─── HTTP -> HTTPS Redirect ────────────────────────────────
server {
listen 80;
server_name local.casebender.com;
return 301 https://$server_name$request_uri;
}
# ─── Main HTTPS Server ─────────────────────────────────────
server {
listen 443 ssl;
http2 on;
server_name local.casebender.com;
ssl_certificate /etc/nginx/certs/local-casebender.crt;
ssl_certificate_key /etc/nginx/certs/local-casebender.key;
ssl_protocols TLSv1.2 TLSv1.3;
client_max_body_size 100M;
# ─── Security Headers ─────────────────────────────────
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
# ─── Ingestion API (integration webhooks) ─────────────
location /api/v1/ingest/ {
limit_req zone=ingest_limit burst=500 nodelay;
proxy_pass http://ingestion_service;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# Legacy ingestion route
location /api/ingest/ {
limit_req zone=ingest_limit burst=500 nodelay;
proxy_pass http://ingestion_service;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# ─── REST API Gateway ─────────────────────────────────
location /api/v1/ {
limit_req zone=api_limit burst=50 nodelay;
proxy_pass http://api_service;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /api/openapi.json {
proxy_pass http://api_service;
proxy_set_header Host $host;
}
# ─── Health Check ─────────────────────────────────────
location /health {
access_log off;
return 200 "healthy";
add_header Content-Type text/plain;
}
# ─── Web Application (catch-all) ──────────────────────
location / {
proxy_pass http://web_app;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Port $server_port;
# WebSocket support
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_connect_timeout 60s;
proxy_send_timeout 60s;
proxy_read_timeout 60s;
}
}
}
```
## Step 5: Create Docker Compose Configuration
Create `docker-compose.yml` with the following content:
```yaml theme={null}
services:
# ─── Core Services ───────────────────────────────────────────
app:
image: casebender/casebender:latest
platform: linux/amd64
ports:
- "3000:3000"
environment:
- AUTH_SECRET=${AUTH_SECRET}
- AUTH_SALT=${AUTH_SALT}
- AUTH_TRUST_HOST=true
- NEXTAUTH_URL=${NEXTAUTH_URL:-https://local.casebender.com}
- NEXTAPP_URL=${NEXTAPP_URL:-https://local.casebender.com}
- LICENSE_SECRET_KEY=${LICENSE_SECRET_KEY}
- LIVEBLOCKS_SECRET_KEY=${LIVEBLOCKS_SECRET_KEY}
- POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL}
- POSTGRES_URL=${POSTGRES_URL}
- POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING}
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "node -e \"require('http').get('http://localhost:3000/api/health', (r) => process.exit(r.statusCode === 200 ? 0 : 1)).on('error', () => process.exit(1))\""]
interval: 10s
timeout: 5s
retries: 5
start_period: 60s
api:
image: casebender/api:latest
platform: linux/amd64
ports:
- "3005:3005"
environment:
- PORT=3005
- POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL}
- POSTGRES_URL=${POSTGRES_URL}
- POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING}
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
- AUTH_SECRET=${AUTH_SECRET}
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
restart: unless-stopped
ingestion:
image: casebender/ingestion:latest
platform: linux/amd64
ports:
- "3003:3003"
environment:
- PORT=3003
- POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL}
- POSTGRES_URL=${POSTGRES_URL}
- POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING}
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
restart: unless-stopped
# ─── Processing Services ─────────────────────────────────────
worker:
image: casebender/worker:latest
platform: linux/amd64
ports:
- "3002:3002"
environment:
- PORT=3002
- POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL}
- POSTGRES_URL=${POSTGRES_URL}
- POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING}
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
restart: unless-stopped
workflow-processor:
image: casebender/workflow-processor:latest
platform: linux/amd64
ports:
- "3001:3001"
environment:
- POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL}
- POSTGRES_URL=${POSTGRES_URL}
- POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING}
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
app:
condition: service_healthy
restart: unless-stopped
misp-processor:
image: casebender/misp-processor:latest
platform: linux/amd64
ports:
- "3004:3004"
environment:
- PORT=3004
- POSTGRES_PRISMA_URL=${POSTGRES_PRISMA_URL}
- POSTGRES_URL=${POSTGRES_URL}
- POSTGRES_URL_NON_POOLING=${POSTGRES_URL_NON_POOLING}
- REDIS_URL=${REDIS_URL:-redis://redis:6379}
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
app:
condition: service_healthy
restart: unless-stopped
# ─── Infrastructure ──────────────────────────────────────────
db:
image: postgres:17
environment:
POSTGRES_USER: superadmin
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-88AlwaysTimeToWin88}
POSTGRES_DB: casebender
ports:
- "5433:5432"
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U superadmin -d casebender"]
interval: 5s
timeout: 5s
retries: 10
start_period: 30s
restart: unless-stopped
redis:
image: redis:7.2-alpine
command: redis-server --protected-mode no
ports:
- "6379:6379"
volumes:
- redis_data:/data
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 5s
timeout: 3s
retries: 5
restart: unless-stopped
minio:
image: quay.io/minio/minio
mem_limit: 512m
command: ["minio", "server", "/data", "--console-address", ":9090"]
environment:
- MINIO_ROOT_USER=minioadmin
- MINIO_ROOT_PASSWORD=minioadmin
ports:
- "9090:9090"
- "9000:9000"
volumes:
- "miniodata:/data"
restart: unless-stopped
# ─── Reverse Proxy ───────────────────────────────────────────
nginx:
image: nginx:alpine
ports:
- "443:443"
- "80:80"
volumes:
- ./nginx.conf:/etc/nginx/nginx.conf:ro
- ./local-casebender.crt:/etc/nginx/certs/local-casebender.crt:ro
- ./local-casebender.key:/etc/nginx/certs/local-casebender.key:ro
depends_on:
app:
condition: service_healthy
restart: unless-stopped
volumes:
miniodata:
pgdata:
redis_data:
```
Need enterprise search (OpenSearch)? The Desktop Installer can add the `search-sync`,
`opensearch`, and `opensearch-dashboards` services for you. For most local evaluations the
default PostgreSQL-based search above is all you need.
## Step 6: Configure Local DNS
Add the following entry to your hosts file:
### For macOS and Linux:
```bash theme={null}
sudo echo "127.0.0.1 local.casebender.com" >> /etc/hosts
```
### For Windows:
Add the following line to `C:\Windows\System32\drivers\etc\hosts`:
```
127.0.0.1 local.casebender.com
```
## Step 7: Start the Application
1. Pull the required images:
```bash theme={null}
docker compose pull
```
2. Start all services:
```bash theme={null}
docker compose up -d
```
3. Monitor the logs:
```bash theme={null}
docker compose logs -f
```
4. Access the application at `https://local.casebender.com`
## Default Login Credentials
After deploying CaseBender, you can log in with the following default credentials:
```
Username: admin@casebender.app
Password: secret1234
```
For security reasons, we strongly recommend changing these default credentials immediately after your first login.
## Troubleshooting
### Common Issues
1. **Certificate Warnings**:
* The browser will show a security warning because we're using a self-signed certificate
* Click "Advanced" and proceed to the website
* For development purposes, this is expected and safe
2. **Port Conflicts**:
* Ensure ports 80, 443, 3000, 3001, 3002, 3003, 3004, 3005, 5433, 6379, 9000, and 9090 are not in use
* If needed, modify the port mappings in docker-compose.yml
3. **Database Connection**:
* Check PostgreSQL logs: `docker compose logs db`
* Verify database credentials in .env
* Ensure the database is running: `docker compose ps db`
4. **Service Dependencies**:
* If services fail to start, check their dependencies:
```bash theme={null}
docker compose ps
docker compose logs [service_name]
```
### Checking Logs
View logs for specific services:
```bash theme={null}
# All services
docker compose logs
# Specific service
docker compose logs [service_name]
# Follow logs
docker compose logs -f [service_name]
```
### Service Management
```bash theme={null}
# Restart a specific service
docker compose restart [service_name]
# Stop all services
docker compose down
# Remove volumes (will delete all data)
docker compose down -v
```
## Next Steps
Now that you have CaseBender running locally, you might want to:
Deploy CaseBender to your production environment
Learn about advanced configuration options
# Access Control
Source: https://docs.casebender.com/en/security/access-control
Role-based access control, privileged access management, cross-team visibility, and API security in CaseBender.
## Role-Based Access Control (RBAC)
CaseBender implements granular RBAC that controls access at every level of the platform.
### Role Hierarchy
| Role | Scope | Capabilities |
| --------------- | -------------- | -------------------------------------------------------------------------------- |
| **Super Admin** | Platform-wide | Full platform configuration, user management, security settings, all data access |
| **Org Admin** | Organization | Organization settings, team management, integration configuration, all org data |
| **Team Lead** | Team | Team case assignment, workload management, team-level reporting |
| **Analyst** | Assigned work | Case/alert investigation, task completion, comment and observable management |
| **Read-Only** | Assigned scope | View cases, alerts, and dashboards without modification capability |
| **Integration** | API scope | Programmatic access scoped to specific API operations and data types |
### Permission Granularity
Permissions are defined at the resource and action level:
* **Entity Permissions**: Create, read, update, delete for cases, alerts, tasks, observables, comments
* **Administrative Permissions**: User management, team management, organization settings
* **Security Permissions**: RBAC configuration, audit log access, security settings
* **Integration Permissions**: API key management, webhook configuration, external tool settings
* **Compliance Permissions**: Retention policy management, legal hold, evidence collection
### TLP-Based Access Control
In addition to RBAC, the Traffic Light Protocol restricts data visibility:
* Users can only access entities at or below their maximum TLP clearance level
* TLP restrictions are enforced at the database query level (not just UI)
* TLP access checks are logged in the audit trail
* TLP violations generate security alerts
## Privileged Access Management (PAM)
CaseBender implements just-in-time privilege elevation for sensitive operations, ensuring no user has standing privileged access.
### How PAM Works
1. **Request**: User requests elevated privileges for a specific operation
2. **Justification**: User provides a business justification for the elevation
3. **Approval**: Request is routed to an approver (configurable per operation type)
4. **Time-Bound Grant**: Privileges are granted for a limited duration (default: 1 hour)
5. **Audit**: All actions performed during the elevated session are logged with the elevation context
6. **Auto-Revoke**: Privileges are automatically revoked when the time window expires
### Privileged Operations
| Operation | Default Duration | Approval Required |
| ------------------------------ | ---------------- | ----------------- |
| Bulk data deletion | 30 minutes | Yes |
| Security configuration changes | 1 hour | Yes |
| User role elevation | 1 hour | Yes |
| Audit log export | 30 minutes | No (logged) |
| Integration credential access | 15 minutes | Yes |
| Data retention policy changes | 1 hour | Yes |
### PAM Security Features
* **No Standing Privileges**: Elevated access is always temporary
* **Anomaly Detection**: Unusual elevation patterns trigger security alerts
* **Session Recording**: All actions during elevated sessions are captured in detail
* **Dual Approval**: Critical operations can require approval from two separate approvers
* **Emergency Access**: Break-glass procedures for critical incidents with enhanced audit logging
## Cross-Team Case Visibility
CaseBender supports controlled sharing of cases across team boundaries without compromising data isolation.
### Access Grant Types
| Grant Type | Description | Use Case |
| ---------------- | ----------------------------------------------- | -------------------------------- |
| **Direct** | Specific user granted access to a specific case | Cross-functional investigation |
| **Team** | Entire team granted access to a case | Escalation to specialized team |
| **Organization** | All users in an organization can view the case | Major incident with broad impact |
| **Temporary** | Time-limited access that auto-expires | External consultant review |
### Access Levels
* **View**: Read case details, alerts, tasks, and timeline
* **Comment**: View access plus ability to add comments and notes
* **Contribute**: Comment access plus ability to add observables, tasks, and evidence
* **Full**: Complete access including status changes and case management
## API Security
### API Key Management
* **Scoped Keys**: Each API key is restricted to specific operations (read-only, write, admin)
* **Tier-Based Limits**: Standard, Professional, and Enterprise tiers with different rate limits
* **Key Rotation**: API keys can be rotated without downtime (grace period for old key)
* **Expiration**: Optional expiration dates for temporary integrations
* **Usage Tracking**: Per-key usage statistics and anomaly detection
### Rate Limiting
| Tier | Requests/Minute | Burst Limit | Concurrent |
| ---------------- | --------------- | ----------- | ---------- |
| **Standard** | 60 | 100 | 5 |
| **Professional** | 300 | 500 | 20 |
| **Enterprise** | 1,000 | 2,000 | 50 |
Rate limit headers are included in every API response:
```
X-RateLimit-Limit: 300
X-RateLimit-Remaining: 287
X-RateLimit-Reset: 1706745600
```
### Webhook Security
* **HMAC Signatures**: Every webhook delivery is signed with HMAC-SHA256
* **Signature Verification**: Recipients can verify the signature to ensure authenticity
* **Retry Logic**: Failed deliveries are retried with exponential backoff
* **Delivery Logs**: Full delivery history with request/response details
* **IP Allowlisting**: Optional restriction of webhook destinations to approved IP ranges
### Input Validation
All API inputs are validated before processing:
* **Schema Validation**: Zod schemas enforce type safety on every endpoint
* **HTML Sanitization**: User-provided HTML is sanitized to prevent XSS
* **SQL Injection Prevention**: Parameterized queries via Prisma ORM (no raw SQL)
* **SSRF Prevention**: External URL validation blocks private IP ranges and internal hostnames
* **File Upload Validation**: MIME type verification, extension blocking, size limits
## Related Documentation
* [Authentication](/en/security/authentication) — MFA, SSO, and session management
* [Threat Detection](/en/security/behavioral-analytics) — UEBA and insider threat monitoring
* [Audit Logging](/en/security/audit-logging) — Access event logging
# Security Architecture
Source: https://docs.casebender.com/en/security/architecture
CaseBender's Zero Trust architecture, service isolation, network segmentation, and multi-tenant security design.
## Zero Trust Architecture
CaseBender implements a Zero Trust security model aligned with NIST SP 800-207. No service, user, or device is implicitly trusted regardless of network location.
### Core Principles
1. **Verify Explicitly**: Every request is authenticated and authorized based on all available data points — identity, device health, location, service identity, and data classification
2. **Least Privilege Access**: Users and services receive the minimum permissions required for their function, with just-in-time elevation for privileged operations
3. **Assume Breach**: The architecture assumes any component can be compromised and limits blast radius through segmentation and isolation
### Device Trust Assessment
Every client device connecting to CaseBender is assessed for trust level:
| Trust Level | Criteria | Access Granted |
| ------------- | ------------------------------------------------------------------ | -------------------------------------------------- |
| **Full** | Managed device, up-to-date OS, EDR active, compliant configuration | All operations including sensitive data |
| **Elevated** | Known device, recent OS, security software present | Standard operations, restricted sensitive data |
| **Standard** | Authenticated user, basic device info available | Read operations, limited write access |
| **Reduced** | Unknown device or outdated security posture | Read-only access, step-up required for any changes |
| **Untrusted** | Failed device checks or suspicious indicators | Access denied, security alert generated |
### Mutual Service Authentication
Microservices within CaseBender authenticate to each other using HMAC-based mutual authentication:
* Each service has a unique identity and signing key
* Every inter-service request includes a cryptographic signature
* Receiving services verify the signature before processing
* Replay attacks are prevented with timestamp-based nonce validation
* Key rotation is automated and does not require service restarts
### Step-Up Authentication
Sensitive operations require re-authentication regardless of existing session validity:
* **Bulk operations**: Deleting or modifying more than 10 entities
* **Configuration changes**: Security settings, integration credentials, RBAC policies
* **Privileged access**: PAM elevation requests, role assignments
* **Data export**: Bulk data exports, audit log downloads
* **Administrative actions**: User management, organization settings
## Service Architecture
CaseBender is composed of isolated microservices, each with a single responsibility:
### Service Inventory
| Service | Purpose | Exposed Ports | External Access |
| ---------------------- | --------------------------------------------------- | ------------- | ----------------------- |
| **web** | Next.js application server, UI, and tRPC API | 3000 | Yes (via reverse proxy) |
| **api** | RESTful API for external integrations | 4000 | Yes (via reverse proxy) |
| **worker** | Background job processing (alerts, enrichment, SLA) | None | No |
| **ingestion** | Alert ingestion from external sources | 4100 | Yes (via reverse proxy) |
| **workflow-processor** | Playbook and workflow execution | None | No |
| **misp-processor** | MISP threat intelligence processing | None | No |
| **search-sync** | Elasticsearch synchronization | None | No |
### Service Isolation
* Each service runs in its own container with a dedicated non-root user
* Services that do not need external access have no exposed ports
* Inter-service communication uses authenticated internal channels
* Each service has its own resource limits (CPU, memory)
* Container images use minimal Alpine Linux base images to reduce attack surface
## Network Security
### Segmentation
CaseBender's network architecture separates concerns into distinct zones:
* **Public Zone**: Reverse proxy / load balancer (the only externally accessible component)
* **Application Zone**: Web, API, and ingestion services (accessible only from public zone)
* **Processing Zone**: Worker, workflow-processor, misp-processor, search-sync (no external access)
* **Data Zone**: PostgreSQL, Redis, Elasticsearch (accessible only from application and processing zones)
### Communication Security
* All external traffic requires TLS 1.3 (TLS 1.2 minimum with strong cipher suites)
* Inter-service communication uses mutual TLS or HMAC authentication
* Database connections are encrypted with SSL certificates
* Redis connections use AUTH and TLS
* Elasticsearch connections use API key authentication over TLS
### Rate Limiting
CaseBender implements multi-layer rate limiting:
* **Global**: Protects the entire platform from volumetric attacks
* **Per-API-Key**: Tier-based limits (Standard, Professional, Enterprise)
* **Per-Endpoint**: Sensitive endpoints (login, password reset) have stricter limits
* **Sliding Window**: Prevents burst attacks while allowing legitimate traffic patterns
## Multi-Tenant Security
### Tenant Isolation
CaseBender supports multi-tenant deployments with strict data isolation:
* **Database-Level**: Every query is scoped to the tenant's `organizationId` — there is no way to query across tenants
* **Application-Level**: Middleware enforces tenant context on every request before it reaches business logic
* **API-Level**: API keys are scoped to a specific tenant and cannot access other tenants' data
* **Search-Level**: Elasticsearch indices are tenant-scoped with filtered aliases
### TLP Classification
The Traffic Light Protocol (TLP) provides an additional layer of data access control:
| TLP Level | Visibility | Use Case |
| -------------------- | ------------------------------------- | --------------------------------------------------- |
| **TLP:RED** | Named recipients only | Active incident details, threat actor attribution |
| **TLP:AMBER+STRICT** | Organization only, restricted sharing | Vulnerability details, internal investigation notes |
| **TLP:AMBER** | Organization and clients | Threat intelligence, remediation guidance |
| **TLP:GREEN** | Community-wide | General security advisories, best practices |
| **TLP:CLEAR** | Unrestricted | Public information, published CVEs |
TLP classifications propagate automatically from cases to child entities (alerts, tasks, observables) and are enforced at the query level.
## Container Security
### Build-Time Hardening
Every CaseBender container image follows security best practices:
* **Multi-Stage Builds**: Build dependencies are not included in production images
* **Non-Root Users**: All services run as dedicated non-root users
* **Minimal Base Images**: Alpine Linux to minimize attack surface
* **Pinned Dependencies**: All system packages and tools are version-pinned
* **Frozen Lockfiles**: `pnpm install --frozen-lockfile` ensures reproducible builds
* **No Secrets in Images**: All secrets are injected at runtime via environment variables or secrets providers
### Runtime Hardening
* Read-only root filesystem (where supported)
* Dropped Linux capabilities
* Resource limits (CPU, memory, file descriptors)
* Health check endpoints for orchestrator monitoring
* Graceful shutdown handling for zero-downtime deployments
## Related Documentation
* [Data Protection](/en/security/data-protection) — Encryption, classification, and secrets management
* [Authentication](/en/security/authentication) — MFA, SSO, and session management
* [Supply Chain Security](/en/security/supply-chain) — Container signing and build verification
* [Hardening Guide](/en/security/hardening-guide) — Deployment hardening recommendations
# Audit Logging
Source: https://docs.casebender.com/en/security/audit-logging
CaseBender's unified audit trail, integrity verification, SIEM forwarding, legal hold, and e-discovery support.
## Unified Audit Trail
CaseBender maintains a comprehensive, tamper-evident audit trail that records every significant action across the platform. The audit system is designed to satisfy the most stringent compliance requirements (SOC2 CC7.2, ISO 27001 A.8.15, HIPAA 164.312(b), CMMC AU.L2-3.3.1).
### What's Logged
Every audit entry captures:
| Field | Description |
| -------------------- | ------------------------------------------------------------------------ |
| **Timestamp** | Precise UTC timestamp of the action |
| **Actor** | Who performed the action (user, system, integration, or API key) |
| **Action** | What was done (create, read, update, delete, export, authenticate, etc.) |
| **Target** | What entity was affected (case, alert, task, user, configuration, etc.) |
| **Changes** | Before and after values for modifications |
| **Context** | IP address, user agent, session ID, tenant ID |
| **Compliance Flags** | Which compliance frameworks this event satisfies |
### Event Categories
| Category | Examples |
| ------------------- | --------------------------------------------------------------------- |
| **Entity Access** | Case viewed, alert accessed, evidence downloaded |
| **Entity Changes** | Case updated, alert status changed, task assigned |
| **Authentication** | Login, logout, MFA challenge, SSO assertion, lockout |
| **Authorization** | Access granted, access denied, privilege elevated, role changed |
| **System Events** | Service started, configuration changed, backup completed |
| **Data Export** | Audit log exported, case data exported, report generated |
| **Security Events** | Anomaly detected, threat indicator triggered, policy violation |
| **Bulk Operations** | Bulk update, bulk delete, bulk assign (with individual item tracking) |
### Query and Search
The audit trail supports powerful querying:
* **Full-Text Search**: Search across all audit fields
* **Filtered Views**: Filter by date range, actor, action type, entity type, and more
* **Saved Filters**: Save commonly used filter combinations
* **Export**: Export filtered results in PDF, CSV, or structured JSON
* **Scheduled Reports**: Configure recurring audit reports delivered via email
## Audit Integrity
### Tamper-Evident Hash Chains
CaseBender protects audit log integrity using cryptographic hash chains:
* Each audit entry includes a SHA-256 hash of the previous entry
* This creates an immutable chain — modifying any entry would break the chain
* Integrity verification can detect tampering at any point in the chain
* Verification can be performed on-demand or on a schedule
### Integrity Verification
* **On-Demand Verification**: Administrators can verify audit log integrity at any time
* **Scheduled Verification**: Automated integrity checks run on a configurable schedule
* **Verification Report**: Detailed report showing chain integrity status, any gaps, and anomalies
* **Alert on Tampering**: If integrity verification fails, a security alert is generated immediately
Audit log integrity verification satisfies SEC Rule 17a-4 (WORM storage equivalent), SOC2 CC7.2 (system monitoring), and ISO 27001 A.8.15 (logging).
## SIEM Forwarding
CaseBender forwards audit events to your existing SIEM in real-time for centralized security monitoring.
### Supported Destinations
| Destination | Protocol | Formats |
| ---------------------- | -------------------------- | --------------------- |
| **Splunk** | HTTP Event Collector (HEC) | JSON, CEF |
| **Elastic / ELK** | Elasticsearch API | JSON (ECS-compatible) |
| **IBM QRadar** | Syslog (TCP/TLS) | LEEF |
| **Microsoft Sentinel** | Log Analytics API | JSON |
| **Generic Syslog** | Syslog (TCP/UDP/TLS) | CEF, LEEF, JSON |
| **Custom Webhook** | HTTPS POST | JSON |
### Forwarding Features
* **Multiple Destinations**: Forward to multiple SIEMs simultaneously
* **Event Filtering**: Choose which event categories to forward
* **Buffering**: Events are buffered during SIEM outages and delivered when connectivity is restored
* **Retry Logic**: Failed deliveries are retried with exponential backoff
* **TLS Encryption**: All forwarded events are encrypted in transit
* **Health Monitoring**: Forwarding health is monitored with alerts on delivery failures
## Legal Hold
CaseBender includes a legal hold system for litigation preservation:
### Legal Hold Management
* **Hold Creation**: Create legal holds with scope, custodians, and preservation requirements
* **Scope Definition**: Define what data is preserved (cases, alerts, evidence, communications)
* **Custodian Management**: Track custodians (individuals responsible for preserving data)
* **Evidence Preservation**: Entities under legal hold are exempt from automated retention/deletion
* **Hold Release**: Release holds when litigation concludes, with full audit trail
### Legal Hold Features
| Feature | Description |
| -------------------------- | --------------------------------------------------------- |
| **Automatic Preservation** | Entities matching hold scope are automatically preserved |
| **Retention Override** | Legal holds override data retention policies |
| **Custodian Notification** | Custodians are notified of their preservation obligations |
| **Compliance Tracking** | Track custodian acknowledgment and compliance |
| **Chain of Custody** | Maintain evidence chain of custody documentation |
| **Audit Trail** | All hold actions are logged in the audit trail |
## E-Discovery Support
CaseBender supports the full e-discovery lifecycle:
### E-Discovery Workflow
1. **Request**: Receive and track e-discovery requests with deadlines and scope
2. **Collection**: Collect responsive data from cases, alerts, comments, and audit logs
3. **Review**: Review collected data in dedicated review sets with tagging and annotation
4. **Production**: Produce responsive documents in required formats
5. **Export**: Generate export packages for legal counsel
### Review Capabilities
* **Review Sets**: Organize collected data into review sets for efficient review
* **Tagging**: Tag documents as responsive, privileged, or irrelevant
* **Bulk Review**: Review multiple items simultaneously with consistent tagging
* **Decision Tracking**: Track review decisions with reviewer attribution
* **Export Formats**: PDF, CSV, native format, and structured data packages
## Data Retention for Audit Logs
Audit logs follow configurable retention policies:
| Data Type | Default Retention | Compliance Requirement |
| --------------------- | ----------------- | ---------------------- |
| Authentication events | 3 years | SOC2, ISO 27001, CMMC |
| Authorization events | 3 years | SOC2, ISO 27001, HIPAA |
| Data access events | 3 years | GDPR, HIPAA, PCI DSS |
| Configuration changes | 7 years | SEC Rule 17a-4 |
| Security events | 3 years | SOC2, CMMC, FedRAMP |
| Compliance evidence | 7 years | Multiple frameworks |
Audit logs under legal hold are retained indefinitely regardless of retention policy settings.
## Related Documentation
* [Security Architecture](/en/security/architecture) — How audit logging fits into the security design
* [Compliance Overview](/en/security/compliance-overview) — How audit logs provide compliance evidence
* [Threat Detection](/en/security/behavioral-analytics) — UEBA and SIEM integration
# Authentication
Source: https://docs.casebender.com/en/security/authentication
Multi-factor authentication, SSO, account lockout, and step-up authentication in CaseBender.
## Multi-Factor Authentication
CaseBender supports multiple MFA methods to protect user accounts. MFA can be enforced at the organization level, ensuring all users comply with your security policy.
### TOTP (Time-Based One-Time Password)
Standard TOTP authentication compatible with all major authenticator apps:
* **Google Authenticator**
* **Microsoft Authenticator**
* **Authy**
* **1Password**
* Any TOTP-compatible app (RFC 6238)
Setup process:
1. User navigates to Security Settings
2. Scans QR code with their authenticator app
3. Enters a verification code to confirm enrollment
4. Backup codes are generated for account recovery
### WebAuthn / FIDO2 Hardware Tokens
For organizations requiring phishing-resistant authentication:
* **YubiKey** (USB-A, USB-C, NFC)
* **Google Titan** Security Keys
* **Windows Hello** (biometric)
* **Apple Touch ID / Face ID** (platform authenticators)
* Any FIDO2-compliant authenticator
WebAuthn provides the strongest authentication because:
* Credentials are bound to the origin (phishing-resistant)
* Private keys never leave the hardware token
* No shared secrets that can be intercepted
* Supports user verification (PIN or biometric)
### Backup Codes
When enrolling in MFA, users receive one-time backup codes for account recovery:
* 10 single-use codes generated at enrollment
* Each code can only be used once
* Codes are hashed before storage (cannot be retrieved, only verified)
* New codes can be regenerated (invalidates all previous codes)
## Single Sign-On (SSO)
### SAML 2.0
CaseBender supports SAML 2.0 for enterprise SSO integration:
* **Identity Providers**: Okta, Azure AD, OneLogin, PingFederate, ADFS, and any SAML 2.0 compliant IdP
* **SP-Initiated SSO**: Users start at CaseBender and are redirected to the IdP
* **IdP-Initiated SSO**: Users start at the IdP portal and are directed to CaseBender
* **Single Logout (SLO)**: Logging out of CaseBender terminates the IdP session
* **Attribute Mapping**: Map IdP attributes to CaseBender user fields (name, email, role, team)
### SCIM Provisioning
Automate user lifecycle management with SCIM 2.0:
* **User Provisioning**: Automatically create CaseBender accounts when users are added in your IdP
* **User Deprovisioning**: Automatically disable accounts when users are removed from the IdP
* **Group Sync**: Map IdP groups to CaseBender teams and roles
* **Profile Updates**: Changes in the IdP (name, email, department) sync to CaseBender automatically
### Just-In-Time (JIT) Provisioning
For organizations that prefer not to use SCIM:
* Users are automatically created on first SSO login
* Default role and team assignments are configurable
* Attribute mapping determines initial permissions
* Administrators can review and adjust JIT-provisioned accounts
## Account Lockout
CaseBender implements progressive account lockout to prevent brute-force attacks:
### Lockout Policy
| Attempt | Action |
| ------- | ---------------------------------------- |
| 1-4 | Normal login flow |
| 5 | Account locked for 5 minutes |
| 6-9 | Extended lockout with progressive delays |
| 10+ | Account locked until admin intervention |
### Lockout Features
* **Progressive Delays**: Each subsequent lockout increases the wait time
* **IP-Based Tracking**: Failed attempts are tracked per IP address in addition to per account
* **Admin Unlock**: Administrators can manually unlock accounts
* **Notification**: Users and administrators are notified of lockout events
* **Audit Trail**: All lockout events are logged with IP address, user agent, and timestamp
## Step-Up Authentication
Even with a valid session, CaseBender requires re-authentication for sensitive operations:
### Operations Requiring Step-Up
* Changing security settings (MFA, SSO configuration)
* Modifying RBAC policies or role assignments
* Bulk delete operations (cases, alerts, tasks)
* Exporting audit logs or sensitive data
* Privileged access elevation (PAM)
* Changing integration credentials
* Modifying data retention policies
### Step-Up Methods
Users can satisfy step-up requirements using any enrolled MFA method:
* TOTP code from authenticator app
* WebAuthn/FIDO2 hardware token tap
* Backup code (one-time use)
Step-up sessions have a configurable expiry (default: 15 minutes) after which re-authentication is required again.
## Session Management
* **Configurable Session Duration**: Organizations can set session timeout policies
* **Concurrent Session Limits**: Configurable maximum concurrent sessions per user
* **Session Revocation**: Administrators can terminate any user's active sessions
* **Idle Timeout**: Sessions expire after configurable inactivity period
* **Secure Cookies**: HTTP-only, Secure, SameSite=Strict cookie attributes
## Related Documentation
* [Access Control](/en/security/access-control) — RBAC, PAM, and API security
* [Security Architecture](/en/security/architecture) — Zero Trust design principles
* [Audit Logging](/en/security/audit-logging) — Authentication event logging
# Threat Detection
Source: https://docs.casebender.com/en/security/behavioral-analytics
User and Entity Behavior Analytics (UEBA), insider threat detection, DDoS protection, and SIEM integration.
## User and Entity Behavior Analytics (UEBA)
CaseBender includes a built-in UEBA engine that establishes behavioral baselines for every user and detects anomalies that may indicate compromised accounts or malicious activity.
### Behavioral Categories Monitored
| Category | What's Tracked | Example Anomaly |
| ------------------- | ----------------------------------------------- | ------------------------------------------ |
| **Authentication** | Login times, locations, devices, MFA usage | Login from new country at unusual hour |
| **Data Access** | Cases viewed, searches performed, exports | Bulk case access outside normal pattern |
| **Case Operations** | Cases created, modified, closed, reassigned | Unusual volume of case closures |
| **Administrative** | Settings changes, user management, role changes | Privilege escalation outside change window |
| **API Usage** | Endpoint access patterns, data volumes | Sudden spike in API calls from a key |
| **Communication** | Comments, notifications, sharing patterns | Mass sharing of restricted cases |
### How Baselines Work
1. **Learning Period**: The system observes user behavior for a configurable baseline window (default: 30 days)
2. **Feature Extraction**: Behavioral features are extracted (time patterns, volume patterns, entity patterns)
3. **Baseline Establishment**: Statistical baselines are created per user and per peer group
4. **Continuous Comparison**: Every action is compared against the user's baseline and their peer group
5. **Anomaly Scoring**: Deviations are scored based on magnitude, frequency, and risk context
### Peer Group Analysis
Users are automatically grouped by role, team, and behavior patterns. Anomalies are evaluated both against individual baselines and peer group norms:
* A SOC analyst accessing 50 cases per day is normal if their peers do the same
* The same access pattern from a user who normally accesses 5 cases per day is anomalous
* Peer group deviations are weighted differently from individual deviations
### Risk Scoring
Each user maintains a dynamic risk score:
| Risk Level | Score Range | Response |
| ------------ | ----------- | ------------------------------------------------------------------------------ |
| **Critical** | 90-100 | Immediate alert to security team, session review, potential account suspension |
| **High** | 70-89 | Alert generated, enhanced monitoring enabled, manager notified |
| **Medium** | 40-69 | Logged for review, included in daily security digest |
| **Low** | 10-39 | Normal monitoring, baseline adjustment |
| **Minimal** | 0-9 | Standard operations |
### ML Adapter
CaseBender's UEBA engine includes an ML adapter interface for organizations that want to integrate advanced machine learning models:
* Feature vector extraction for external ML pipelines
* Anomaly prediction integration
* Model health monitoring
* Supports custom model deployment alongside built-in statistical detection
## Insider Threat Detection
CaseBender provides dedicated insider threat detection capabilities that go beyond UEBA to include investigation workflows, watchlists, and escalation management.
### Threat Indicators
The system monitors for indicators across multiple categories:
* **Data Exfiltration**: Unusual export volumes, bulk downloads, access to cases outside assignment
* **Privilege Abuse**: Unauthorized configuration changes, role manipulation, PAM misuse
* **Policy Violations**: Access outside business hours, from unauthorized locations, bypassing controls
* **Behavioral Changes**: Sudden changes in work patterns, increased access to sensitive data
* **Pre-Departure Risk**: Access pattern changes correlated with HR signals (resignation, termination)
### Investigation Workflow
When indicators are detected:
1. **Alert Generation**: Insider threat alert created with risk score and indicator details
2. **Triage**: Security team reviews the alert and determines if investigation is warranted
3. **Investigation**: Dedicated investigation workspace with timeline, evidence collection, and notes
4. **Watchlist**: Users can be placed on enhanced monitoring watchlists with configurable monitoring levels
5. **Escalation**: Configurable escalation rules route investigations to appropriate teams (security, HR, legal)
6. **Resolution**: Investigations are closed with documented findings and actions taken
### Integration Points
* **HR Systems**: Receive employment status changes (resignation, termination, role change) to adjust risk scoring
* **SIEM**: Forward insider threat events to your SIEM for correlation with other security data
* **Legal Hold**: Automatically initiate legal holds when investigations reach certain severity thresholds
* **Notification**: Alert security managers, HR, and legal teams based on escalation rules
## DDoS Protection
CaseBender includes application-layer DDoS detection and mitigation:
### Detection Methods
* **Traffic Analysis**: Real-time monitoring of request rates, patterns, and sources
* **Request Fingerprinting**: Identifies coordinated attacks from distributed sources
* **Geo-Blocking**: Configurable country-level blocking for regions with no legitimate users
* **Anomaly Detection**: Statistical analysis of traffic patterns against established baselines
### Mitigation
* **Automatic Rate Limiting**: Progressive rate limiting as attack severity increases
* **Challenge Pages**: CAPTCHA challenges for suspicious traffic patterns
* **IP Blocking**: Temporary or permanent blocking of identified attack sources
* **Alerting**: Real-time alerts to operations team with attack details and mitigation status
CaseBender's DDoS protection operates at the application layer. For volumetric network-layer DDoS protection, deploy CaseBender behind a dedicated DDoS mitigation service (e.g., Cloudflare, AWS Shield, or on-premise appliances).
## SIEM Integration
CaseBender forwards security events to your existing SIEM for centralized monitoring and correlation.
### Supported Destinations
| SIEM | Protocol | Format |
| ---------------------- | -------------------------- | --------------- |
| **Splunk** | HTTP Event Collector (HEC) | JSON, CEF |
| **Elastic / ELK** | Elasticsearch API | JSON (ECS) |
| **IBM QRadar** | Syslog | LEEF |
| **Microsoft Sentinel** | Log Analytics API | JSON |
| **Generic Syslog** | Syslog (TCP/UDP/TLS) | CEF, LEEF, JSON |
| **Custom Webhook** | HTTPS POST | JSON |
### Events Forwarded
* Authentication events (login, logout, MFA, lockout)
* Authorization events (access granted, denied, elevated)
* Data access events (entity viewed, exported, modified)
* Security events (anomaly detected, threat indicator, policy violation)
* Administrative events (configuration change, user management)
* System events (service health, error conditions)
### Configuration
SIEM forwarding is configured per organization:
* Multiple destinations can be configured simultaneously
* Event filtering controls which event types are forwarded
* Buffering and retry logic ensures no events are lost during SIEM outages
* TLS encryption for all forwarded events
## Related Documentation
* [Access Control](/en/security/access-control) — RBAC and PAM that generate the events UEBA monitors
* [Audit Logging](/en/security/audit-logging) — The audit trail that feeds UEBA and SIEM
* [Security Architecture](/en/security/architecture) — Zero Trust design that UEBA enforces
# Code Security
Source: https://docs.casebender.com/en/security/code-security
Static analysis, dynamic testing, vulnerability management, penetration testing, and license compliance in CaseBender.
## Overview
CaseBender's code security program covers the entire software development lifecycle — from static analysis during development to dynamic testing in staging, continuous vulnerability monitoring in production, and regular penetration testing by third parties.
### Live Security Scan Status

This badge represents 12 automated security checks that run on every code change.
## Static Application Security Testing (SAST)
### ESLint Security Rules
Every pull request is scanned with ESLint security rules that detect:
* Use of `eval()` and `Function()` constructor
* `dangerouslySetInnerHTML` in React components
* Hardcoded secrets and credentials
* Insecure regular expressions (ReDoS)
* Prototype pollution patterns
### Semgrep Deep Analysis
[Semgrep](https://semgrep.dev/) provides deep taint analysis across the TypeScript and Next.js codebase:
* **OWASP Top 10 Rules**: Injection, broken authentication, sensitive data exposure, XSS, insecure deserialization
* **TypeScript-Specific Rules**: Type confusion, unsafe type assertions, prototype pollution
* **Next.js-Specific Rules**: Server-side request forgery, open redirects, insecure API routes
* **Custom Rules**: CaseBender-specific patterns for common security mistakes
### Secret Detection
[Gitleaks](https://gitleaks.io/) scans every commit for accidentally committed secrets:
* API keys and tokens
* Database connection strings
* Private keys and certificates
* Cloud provider credentials
* Generic high-entropy strings
Gitleaks scans both the current commit and the full git history to catch secrets that may have been committed and later removed.
## Dynamic Application Security Testing (DAST)
### OWASP ZAP
[OWASP ZAP](https://www.zaproxy.org/) performs full active scanning against the running application:
* **Schedule**: Weekly (every Sunday at 2 AM UTC)
* **Scan Type**: Full active scan (not just passive observation)
* **Target**: Complete application surface including API endpoints
* **Results**: SARIF format uploaded to GitHub Code Scanning
### What ZAP Tests
* SQL injection
* Cross-site scripting (XSS)
* Cross-site request forgery (CSRF)
* Server-side request forgery (SSRF)
* Directory traversal
* Remote code execution
* Authentication bypass
* Session management flaws
* Information disclosure
## Vulnerability Management
### Continuous Scanning
Vulnerabilities are detected through multiple channels:
| Scanner | Target | Schedule | Severity Gate |
| ---------------------------- | --------------------------------- | ---------- | -------------------------- |
| **Trivy (Filesystem)** | npm dependencies | Every PR | CRITICAL, HIGH |
| **Trivy (Container)** | Container images (all 7 services) | Every PR | CRITICAL, HIGH |
| **Trivy (IaC)** | Dockerfiles, Kubernetes configs | Every PR | CRITICAL, HIGH |
| **pnpm audit** | Production dependencies | Every PR | CRITICAL, HIGH |
| **Dependabot** | All dependencies | Continuous | Automatic PRs |
| **GitHub Dependency Review** | New/changed dependencies | Every PR | CRITICAL, HIGH block merge |
### Vulnerability SLAs
When vulnerabilities are discovered, they must be remediated within defined SLAs:
| Severity | Remediation SLA | Escalation |
| ---------------------------- | --------------- | --------------------------- |
| **Critical** (CVSS 9.0-10.0) | 24 hours | Immediate team notification |
| **High** (CVSS 7.0-8.9) | 7 days | Daily standup review |
| **Medium** (CVSS 4.0-6.9) | 30 days | Weekly review |
| **Low** (CVSS 0.1-3.9) | 90 days | Quarterly review |
### Risk Acceptance
When a vulnerability cannot be immediately remediated (e.g., no patch available), CaseBender follows a formal risk acceptance process:
1. **Documentation**: Vulnerability details, affected components, and business impact
2. **Justification**: Why remediation is not immediately possible
3. **Mitigation**: Compensating controls in place to reduce risk
4. **Review Date**: Mandatory review date (maximum 90 days)
5. **Approval**: Security team approval required
Risk acceptances are tracked in `.trivyignore` with full documentation and quarterly review.
## Penetration Testing
CaseBender includes a penetration testing management module:
### Engagement Management
* **Engagement Tracking**: Schedule and track penetration testing engagements
* **Scope Definition**: Define testing scope, rules of engagement, and authorized techniques
* **Finding Management**: Track findings with severity, status, and remediation progress
* **Remediation SLAs**: Findings must be remediated within severity-based SLAs
### Remediation SLAs
| Finding Severity | Remediation Deadline |
| ----------------- | -------------------- |
| **Critical** | 15 days |
| **High** | 30 days |
| **Medium** | 60 days |
| **Low** | 90 days |
| **Informational** | Next release cycle |
## License Compliance
### Automated License Scanning
Every dependency's license is checked automatically:
* **Blocked Licenses**: Copyleft licenses (GPL, AGPL, LGPL) are blocked from entering the codebase
* **Allowed Licenses**: MIT, Apache 2.0, BSD, ISC, and other permissive licenses
* **Review Required**: Uncommon or unknown licenses are flagged for legal review
* **No License**: Dependencies without a declared license are blocked
### License Scanning Pipeline
Trivy performs license scanning as part of the security scan workflow:
```
Dependency Added → License Detected → Policy Check → Allowed / Blocked / Review Required
```
## Input Validation
CaseBender implements comprehensive input validation to prevent injection attacks:
### HTML Sanitization
* All user-provided HTML (comments, descriptions) is sanitized before storage and rendering
* Allowlisted tags and attributes only
* Script tags, event handlers, and data URIs are stripped
### File Upload Validation
* MIME type verification (not just extension checking)
* Blocked extensions: `.exe`, `.bat`, `.cmd`, `.ps1`, `.sh`, `.dll`, `.so`
* Maximum file size enforcement (configurable per upload type)
* Evidence uploads have separate, stricter validation
### URL Validation (SSRF Prevention)
* External URLs are validated before any server-side requests
* Private IP ranges (10.x, 172.16-31.x, 192.168.x, 127.x) are blocked
* Internal hostnames and cloud metadata endpoints are blocked
* DNS rebinding protection via pre-resolution validation
### Request Sanitization
* Null byte stripping from all string inputs
* Unicode normalization to prevent homograph attacks
* Zod schema validation on every API endpoint
* Parameterized queries via Prisma ORM (no raw SQL)
## Security Gate
All security checks must pass before code can be merged to the main branch:
```
PR Created
├── Gitleaks (secret detection)
├── Trivy (dependency scan)
├── Trivy (container scan × 7 services)
├── Trivy (IaC scan)
├── ESLint Security
├── Semgrep SAST
├── pnpm audit
├── License compliance
├── Dependency review
└── Supply chain verification
│
▼
Security Gate (all must pass)
│
▼
Merge Allowed
```
The security gate is enforced via GitHub branch protection rules. It cannot be bypassed, even by repository administrators.
## Related Documentation
* [Supply Chain Security](/en/security/supply-chain) — Container signing, SBOM, and provenance
* [Security Overview](/en/security/overview) — Live pipeline status
* [Hardening Guide](/en/security/hardening-guide) — Deployment security recommendations
# Additional Compliance Frameworks
Source: https://docs.casebender.com/en/security/compliance-additional
CaseBender's support for CMMC, FedRAMP, HIPAA, PCI DSS, Export Control, and EU AI Act compliance.
## CMMC Level 2
CaseBender supports Cybersecurity Maturity Model Certification (CMMC) Level 2, which requires implementation of 110 practices from NIST SP 800-171.
### Key Capabilities
* **Practice Management**: Track all 110 CMMC Level 2 practices across 14 domains
* **SPRS Scoring**: Calculate and track your Supplier Performance Risk System (SPRS) score over time
* **Assessment Tracking**: Manage self-assessments and third-party assessments (C3PAO)
* **POA\&M Management**: Track Plans of Action and Milestones for practices not yet fully implemented
* **Evidence Collection**: Automated collectors gather evidence mapped to specific practices
### Domain Coverage
| Domain | Practices | Description |
| ----------------------------------------- | --------- | ------------------------------------------------------- |
| **AC** Access Control | 22 | Account management, access enforcement, remote access |
| **AT** Awareness & Training | 3 | Security awareness, role-based training |
| **AU** Audit & Accountability | 9 | Audit logging, audit review, audit protection |
| **CM** Configuration Management | 9 | Baseline configuration, change control |
| **IA** Identification & Authentication | 11 | MFA, device authentication, credential management |
| **IR** Incident Response | 3 | Incident handling, reporting, testing |
| **MA** Maintenance | 6 | System maintenance, maintenance tools |
| **MP** Media Protection | 4 | Media access, storage, transport |
| **PE** Physical Protection | 6 | Physical access, monitoring, visitor control |
| **PS** Personnel Security | 2 | Personnel screening, termination |
| **RA** Risk Assessment | 3 | Risk assessment, vulnerability scanning |
| **CA** Security Assessment | 4 | Assessment, monitoring, system connections |
| **SC** System & Communications Protection | 16 | Boundary protection, encryption, key management |
| **SI** System & Information Integrity | 7 | Flaw remediation, malicious code protection, monitoring |
***
## FedRAMP Moderate
CaseBender supports FedRAMP Moderate authorization, implementing controls from NIST SP 800-53 Rev 5.
### Key Capabilities
* **Control Management**: Track all 325 FedRAMP Moderate controls with implementation status
* **System Security Plan (SSP)**: Manage SSP documentation with version control and approval workflows
* **Continuous Monitoring (ConMon)**: Automated monthly reporting on control effectiveness
* **POA\&M Management**: Track remediation plans with OMB A-130 compliance
* **Authorization Periods**: Manage authorization boundaries, ATOs, and reauthorization schedules
* **Significant Change Management**: Track and assess significant changes that may affect authorization
### Control Families
CaseBender maps its capabilities to all 20 NIST SP 800-53 control families, with particular strength in:
* **AC** (Access Control): RBAC, MFA, session management, PAM
* **AU** (Audit and Accountability): Unified audit trail, integrity protection, SIEM forwarding
* **IA** (Identification and Authentication): Multi-factor, device trust, service authentication
* **IR** (Incident Response): Case management, playbooks, SLA tracking
* **SC** (System and Communications Protection): Encryption, TLS, network segmentation
***
## HIPAA
CaseBender supports HIPAA compliance for organizations that handle Protected Health Information (PHI) as part of security operations.
### Security Rule Safeguards
#### Administrative Safeguards (164.308)
| Safeguard | CaseBender Implementation |
| -------------------------------- | ---------------------------------------------------------------- |
| Security Management Process | Risk assessment, vulnerability management, security monitoring |
| Assigned Security Responsibility | RBAC with defined security roles |
| Workforce Security | SCIM provisioning, access termination, insider threat monitoring |
| Information Access Management | TLP-based access control, data classification, PAM |
| Security Awareness & Training | Compliance training module with HIPAA-specific programs |
| Security Incident Procedures | Case management, incident response workflows, SLA tracking |
| Contingency Plan | Data retention, backup management, disaster recovery |
| Evaluation | Compliance dashboards, control testing, gap analysis |
#### Technical Safeguards (164.312)
| Safeguard | CaseBender Implementation |
| --------------------- | --------------------------------------------------------------------- |
| Access Control | Unique user identification, emergency access, auto-logoff, encryption |
| Audit Controls | Unified audit trail with PHI access logging |
| Integrity | Data integrity verification, tamper-evident audit logs |
| Authentication | MFA, WebAuthn, SSO, account lockout |
| Transmission Security | TLS 1.3, encrypted inter-service communication |
### Breach Notification Rule (164.404-408)
* **Individual Notification**: Generate and track notifications to affected individuals
* **HHS Notification**: Manage notification to the Department of Health and Human Services
* **Media Notification**: For breaches affecting 500+ individuals, manage media notifications
* **Breach Documentation**: Maintain breach records for 6 years as required
### Business Associate Agreements
* Track BAAs with all business associates
* Monitor BAA expiration dates and renewal requirements
* Document BAA terms and data handling obligations
***
## PCI DSS v4.0
CaseBender supports PCI DSS v4.0 for organizations that process payment card data in security investigations.
### Key Capabilities
* **Requirement Tracking**: All 12 PCI DSS requirements with 78 sub-requirements
* **Evidence Collection**: Automated collectors for access controls, encryption, logging, and network security
* **Control Testing**: Scheduled testing with evidence capture and result tracking
* **Incident Management**: PCI-specific incident tracking with notification requirements
* **Assessment Periods**: Manage QSA assessments and self-assessment questionnaires
### Requirement Coverage
| Requirement | Description | CaseBender Mapping |
| ----------- | ----------------------------- | -------------------------------------------------- |
| **1** | Network Security Controls | Network segmentation, firewall configuration |
| **2** | Secure Configurations | Container hardening, configuration management |
| **3** | Protect Stored Data | Encryption at rest, key management, data retention |
| **4** | Protect Data in Transit | TLS 1.3, encrypted communications |
| **5** | Malicious Software Protection | Container scanning, dependency scanning |
| **6** | Secure Development | SAST, DAST, code review, vulnerability management |
| **7** | Restrict Access | RBAC, least privilege, PAM |
| **8** | Identify Users | MFA, unique IDs, authentication management |
| **9** | Physical Access | On-premise deployment documentation |
| **10** | Log and Monitor | Unified audit trail, SIEM forwarding, integrity |
| **11** | Test Security | Penetration testing, vulnerability scanning |
| **12** | Organizational Policies | Policy management, training, incident response |
***
## Export Control
CaseBender includes export control compliance for organizations handling controlled technology data.
### Key Capabilities
* **ECCN/ITAR Classification**: Classify security data and tools under Export Administration Regulations (EAR) and International Traffic in Arms Regulations (ITAR)
* **Denied Party Screening**: Screen entities against government restricted and denied party lists before data sharing
* **Country Controls**: Enforce embargoed and restricted country rules on data access and sharing
* **License Management**: Track export licenses with expiration dates and usage limits
* **Auto-Classification Engine**: Suggest classifications based on data content and context
### Screening Lists
CaseBender screens against:
* Consolidated Screening List (CSL)
* Entity List (BIS)
* Specially Designated Nationals (OFAC SDN)
* Denied Persons List (BIS)
* Debarred List (DDTC)
***
## EU AI Act
CaseBender supports EU AI Act compliance for organizations using AI capabilities within the platform.
### Key Capabilities
* **AI System Registration**: Register and catalog AI systems used within CaseBender (AI insights, auto-enrichment, correlation engine)
* **Risk Assessment**: Evaluate AI systems against EU AI Act risk categories (minimal, limited, high, unacceptable)
* **Incident Reporting**: Report and track AI-related incidents with root cause analysis
* **Conformity Assessment**: Manage conformity assessments for high-risk AI systems
* **Human Oversight**: Document human oversight mechanisms for AI-assisted decisions
* **Transparency**: Maintain transparency records showing how AI systems make recommendations
***
## Related Documentation
* [Compliance Overview](/en/security/compliance-overview) — Framework matrix and unified compliance
* [SOC2 Type II](/en/security/compliance-soc2) — SOC2 deep dive
* [ISO 27001:2022](/en/security/compliance-iso27001) — ISO 27001 deep dive
* [GDPR & Privacy](/en/security/compliance-gdpr) — GDPR deep dive
# GDPR & Privacy
Source: https://docs.casebender.com/en/security/compliance-gdpr
CaseBender's GDPR compliance features including data subject rights, consent management, breach notification, and cross-border transfer controls.
## Overview
CaseBender provides comprehensive GDPR compliance capabilities for organizations that process personal data as part of security operations. As an on-premise platform, CaseBender gives you full control over data processing — your data never leaves your infrastructure.
## Data Subject Rights
### Right of Access (Article 15)
CaseBender supports Data Subject Access Requests (DSARs):
* **Request Management**: Track DSARs from receipt through fulfillment with SLA monitoring
* **Data Discovery**: Automatically discover all data associated with a data subject across cases, alerts, comments, audit logs, and observables
* **Data Export**: Generate structured data packages for data subject delivery
* **Deadline Tracking**: 30-day response deadline with extension management
* **Acknowledgment**: Automated acknowledgment to data subjects upon request receipt
### Right to Erasure (Article 17)
CaseBender implements the right to be forgotten with safeguards:
* **Erasure Execution Engine**: Systematically erases personal data across all platform entities
* **PII Registry**: Comprehensive mapping of where personal data is stored in every database model
* **Anonymization**: Where full deletion would compromise audit integrity, data is anonymized using consistent markers
* **Legal Hold Check**: Erasure requests are automatically checked against active legal holds
* **Verification Report**: Post-erasure verification confirms all personal data has been removed or anonymized
* **Audit Trail**: The erasure action itself is logged (without the erased data) for compliance evidence
### Right to Rectification (Article 16)
* Users can update their personal information through their profile
* Administrators can correct data on behalf of data subjects
* All changes are tracked in the audit trail
### Right to Data Portability (Article 20)
* Data export in structured, machine-readable formats (JSON, CSV)
* Includes all data the subject provided to the platform
* Export packages are encrypted for secure delivery
## Consent Management
### Consent Lifecycle
CaseBender tracks consent throughout its lifecycle:
1. **Collection**: Record consent with purpose, legal basis, and timestamp
2. **Storage**: Consent records are stored with cryptographic integrity
3. **Verification**: Check consent status before processing operations
4. **Withdrawal**: Data subjects can withdraw consent at any time
5. **Impact Assessment**: Withdrawal triggers an impact analysis showing what processing will stop
### Processing Activities Register (Article 30)
Maintain a register of processing activities:
* **Activity Catalog**: Document each processing activity with purpose, legal basis, and data categories
* **Data Flow Mapping**: Track where personal data flows within the platform
* **Retention Periods**: Document retention periods per processing activity
* **Third-Party Sharing**: Record any data sharing with third parties (integrations)
## Breach Notification
### Article 33 — Notification to Supervisory Authority
CaseBender supports the 72-hour breach notification requirement:
* **Breach Detection**: Security monitoring and UEBA detect potential breaches
* **Breach Recording**: Document breach details, affected data, and impact assessment
* **Authority Notification**: Generate notification documents for supervisory authorities
* **Timeline Tracking**: Track the 72-hour deadline with escalation alerts
* **Follow-Up**: Manage supplementary notifications as more information becomes available
### Article 34 — Notification to Data Subjects
When a breach is likely to result in high risk to individuals:
* **Subject Identification**: Identify affected data subjects from breach scope
* **Notification Generation**: Generate clear, plain-language notifications
* **Delivery Tracking**: Track notification delivery and acknowledgment
* **Remediation Guidance**: Include recommended protective measures for affected individuals
## Privacy Impact Assessment
### Automated PIA (Article 35)
CaseBender automates Data Protection Impact Assessments:
* **Personal Data Detection**: Automatically scan entities for personal data patterns
* **Risk Assessment**: Evaluate processing risks based on data types, volume, and sensitivity
* **Mitigation Recommendations**: Suggest privacy-enhancing measures based on identified risks
* **Review Workflow**: PIAs are reviewed and approved by the Data Protection Officer
* **Continuous Monitoring**: PIAs are re-evaluated when processing activities change
## Cross-Border Transfer Controls
### Transfer Safeguards (Articles 44-49)
CaseBender enforces data residency and cross-border transfer rules:
* **Data Residency Policies**: Define where data can be stored and processed by jurisdiction
* **Transfer Rules**: Configure rules for when data can cross borders (adequacy decisions, SCCs, BCRs)
* **Transfer Evaluation**: Automatically evaluate proposed transfers against configured rules
* **Violation Detection**: Detect and alert on unauthorized cross-border data flows
* **Transfer Heatmap**: Visualize data flows across jurisdictions
### Supported Transfer Mechanisms
| Mechanism | Description |
| -------------------------------- | ------------------------------------------------ |
| **Adequacy Decision** | Transfer to countries with EU adequacy decisions |
| **Standard Contractual Clauses** | Transfer under approved SCCs |
| **Binding Corporate Rules** | Intra-group transfers under BCRs |
| **Explicit Consent** | Transfer with explicit data subject consent |
| **Legal Obligation** | Transfer required by law |
## Privacy-Aware Logging
CaseBender implements privacy by design in its logging:
* **PII Redaction**: Personal data is automatically redacted from application logs
* **Configurable Redaction Paths**: Define which fields are redacted in log output
* **Audit vs. Application Logs**: Audit logs retain necessary detail for compliance; application logs are privacy-safe
* **Redaction Strategies**: Support for masking, hashing, and full removal
## Related Documentation
* [Data Protection](/en/security/data-protection) — Encryption and data retention
* [Compliance Overview](/en/security/compliance-overview) — All supported frameworks
* [Audit Logging](/en/security/audit-logging) — Audit trail and integrity
# ISO 27001:2022
Source: https://docs.casebender.com/en/security/compliance-iso27001
CaseBender's ISO 27001:2022 compliance support including ISMS controls, risk management, internal audit, and Statement of Applicability.
## Overview
CaseBender provides comprehensive ISO 27001:2022 Information Security Management System (ISMS) support. The platform maps its security controls to the ISO 27001 Annex A control set and provides tools for risk management, internal audit, and continuous improvement.
## Annex A Control Coverage
### Organizational Controls (A.5)
| Control | Description | CaseBender Implementation |
| ---------- | ------------------------------------------ | ------------------------------------------------------------ |
| **A.5.1** | Policies for information security | Policy management, version control, acknowledgment tracking |
| **A.5.2** | Information security roles | RBAC with defined security responsibilities per role |
| **A.5.3** | Segregation of duties | Role separation, PAM for privileged operations |
| **A.5.7** | Threat intelligence | MITRE ATT\&CK integration, MISP threat feeds, IOC enrichment |
| **A.5.23** | Information security for cloud services | On-premise deployment, cloud hardening guides |
| **A.5.24** | Incident management planning | Case templates, playbook automation, SLA management |
| **A.5.25** | Assessment of information security events | Alert triage workflows, severity scoring, correlation engine |
| **A.5.26** | Response to information security incidents | Case management workflows, task assignment, escalation |
| **A.5.28** | Collection of evidence | Evidence management, chain of custody, legal hold |
### People Controls (A.6)
| Control | Description | CaseBender Implementation |
| --------- | ---------------------------------- | ----------------------------------------------------------------- |
| **A.6.1** | Screening | Integration with HR systems for background check tracking |
| **A.6.3** | Information security awareness | Compliance training module, campaign management |
| **A.6.5** | Responsibilities after termination | SCIM deprovisioning, access revocation, insider threat monitoring |
### Technological Controls (A.8)
| Control | Description | CaseBender Implementation |
| ---------- | ------------------------------ | -------------------------------------------------------------- |
| **A.8.1** | User endpoint devices | Device trust assessment, security posture evaluation |
| **A.8.2** | Privileged access rights | PAM with just-in-time elevation, session recording |
| **A.8.3** | Information access restriction | TLP-based access control, data classification enforcement |
| **A.8.5** | Secure authentication | MFA (TOTP + WebAuthn), SSO (SAML 2.0), account lockout |
| **A.8.9** | Configuration management | Immutable container images, infrastructure as code |
| **A.8.10** | Information deletion | Data retention policies, secure erasure, legal hold exemptions |
| **A.8.11** | Data masking | PII redaction in logs, privacy-aware logging |
| **A.8.12** | Data leakage prevention | Data classification, export controls, UEBA monitoring |
| **A.8.15** | Logging | Unified audit trail, tamper-evident integrity, SIEM forwarding |
| **A.8.16** | Monitoring activities | UEBA, security monitoring, anomaly detection |
| **A.8.24** | Use of cryptography | AES-256 encryption, TLS 1.3, key rotation, secrets management |
## Risk Management
CaseBender includes a dedicated ISO 27001 risk management module:
### Risk Register
* **Risk Identification**: Catalog information security risks with threat and vulnerability mapping
* **Risk Assessment**: Likelihood and impact scoring using configurable risk matrices
* **Risk Treatment**: Define treatment plans with milestones, owners, and deadlines
* **Risk Acceptance**: Formal risk acceptance workflow with management approval and documentation
* **Risk Monitoring**: Track risk levels over time with trend analysis
### Risk Matrix
Risks are evaluated on a 5x5 matrix:
| | Negligible | Minor | Moderate | Major | Catastrophic |
| ------------------ | ---------- | ------ | -------- | -------- | ------------ |
| **Almost Certain** | Medium | High | High | Critical | Critical |
| **Likely** | Low | Medium | High | High | Critical |
| **Possible** | Low | Medium | Medium | High | High |
| **Unlikely** | Low | Low | Medium | Medium | High |
| **Rare** | Low | Low | Low | Medium | Medium |
### Treatment Plans
Each risk treatment plan includes:
* Treatment strategy (mitigate, transfer, accept, avoid)
* Specific actions with owners and deadlines
* Milestones for tracking progress
* Residual risk assessment after treatment
* Review schedule for ongoing monitoring
## Statement of Applicability (SoA)
The SoA documents which Annex A controls are applicable to your deployment:
* **Applicable Controls**: Controls that are relevant and implemented
* **Not Applicable Controls**: Controls excluded with documented justification
* **Implementation Status**: Current implementation level per control
* **Evidence Links**: Direct links to evidence artifacts for each control
* **Approval Workflow**: SoA changes require management approval
## Internal Audit
### Audit Cycle Management
* **Audit Planning**: Define audit scope, schedule, and team assignments
* **Audit Execution**: Guided audit procedures with evidence collection
* **Finding Management**: Track findings by severity (major nonconformity, minor nonconformity, observation, opportunity for improvement)
* **Corrective Actions**: Assign and track corrective actions with deadlines
* **Verification**: Verify corrective action effectiveness before closure
* **Management Review**: Aggregate audit results for management review meetings
### Evidence Collection
Automated collectors gather ISO 27001-specific evidence:
* Access control configurations and reviews
* Security event logs and incident records
* Change management records
* Training and awareness records
* Risk assessment documentation
* Business continuity test results
## Reporting
* **Compliance Dashboard**: Real-time view of ISO 27001 control implementation status
* **Gap Analysis Report**: Identify unimplemented or partially implemented controls
* **Risk Report**: Current risk landscape with treatment status
* **Audit Report**: Internal audit findings and corrective action status
* **Management Review Package**: Aggregated data for management review meetings
## Related Documentation
* [Compliance Overview](/en/security/compliance-overview) — All supported frameworks
* [Data Protection](/en/security/data-protection) — Encryption and data handling controls
* [Threat Detection](/en/security/behavioral-analytics) — Monitoring and detection capabilities
# Compliance Overview
Source: https://docs.casebender.com/en/security/compliance-overview
CaseBender supports 10+ compliance frameworks with built-in evidence collection, control testing, and audit management.
## Compliance Framework Support
CaseBender includes native support for major compliance frameworks. Each framework implementation includes control mapping, automated evidence collection, gap analysis, and reporting — built directly into the platform, not bolted on.
### Framework Matrix
| Framework | Standard | Implementation | Evidence Collection | Reporting |
| -------------------- | ------------------ | ----------------------------------------------------------------------- | ----------------------------------------- | -------------------------------------------- |
| **SOC2 Type II** | AICPA TSC 2017 | Trust Service Criteria mapping, control testing, attestation management | Automated collectors, 3-year retention | Audit period reports, gap analysis |
| **ISO 27001:2022** | ISO/IEC 27001:2022 | Full Annex A controls, Statement of Applicability, risk register | Automated collectors, evidence review | Internal audit reports, management review |
| **GDPR** | EU 2016/679 | Articles 5-88 coverage, DSAR management, consent lifecycle | PII registry, processing activity records | Breach notification, DPIA reports |
| **CMMC Level 2** | NIST SP 800-171 | 110 practices across 14 domains, SPRS scoring | Automated collectors, POA\&M tracking | Assessment reports, SPRS score history |
| **FedRAMP Moderate** | NIST SP 800-53 | 325 controls, continuous monitoring, SSP management | Automated collectors, ConMon reports | Authorization packages, SAR reports |
| **HIPAA** | 45 CFR 160-164 | Security Rule safeguards, breach notification, BAA management | PHI access logging, training records | Disclosure reports, risk assessments |
| **PCI DSS v4.0** | PCI SSC | 12 requirements, 78 sub-requirements | Automated collectors, control testing | Assessment reports, gap analysis |
| **Export Control** | EAR / ITAR | ECCN classification, denied party screening, country controls | Screening logs, license tracking | Transfer reports, compliance dashboards |
| **EU AI Act** | EU 2024/1689 | AI system registration, risk assessment, conformity | Incident reports, oversight records | Risk assessments, transparency reports |
| **Legal Hold** | FRCP / eDiscovery | Litigation preservation, custodian management | Evidence chain of custody | Hold status reports, compliance verification |
### How Compliance Works in CaseBender
Each framework's controls are mapped to CaseBender features and configurations. You can see exactly which platform capabilities satisfy which compliance requirements.
Automated collectors gather evidence from the running platform — audit logs, configuration snapshots, access records — without manual effort.
Identify which controls are fully implemented, partially implemented, or not yet addressed. Prioritize remediation based on risk.
Track audit periods, schedule evidence collection, manage findings, and generate reports for auditors.
## Unified Compliance Dashboard
CaseBender provides a unified view across all enabled compliance frameworks:
### Cross-Framework Visibility
* **Compliance Score**: Aggregate compliance percentage across all frameworks
* **Control Overlap**: Many controls satisfy multiple frameworks simultaneously (e.g., audit logging satisfies SOC2 CC7.2, ISO 27001 A.8.15, CMMC AU.L2-3.3.1, and HIPAA 164.312(b))
* **Gap Prioritization**: Gaps are ranked by how many frameworks they affect
* **Deadline Tracking**: Upcoming audit deadlines, evidence collection schedules, and remediation due dates
* **Activity Feed**: Recent compliance activities across all frameworks
### Regulatory Reporting
* **Automated Report Generation**: Generate framework-specific reports with collected evidence
* **Scheduled Reports**: Configure recurring report generation for continuous compliance
* **Export Formats**: PDF, CSV, and structured data exports for auditor consumption
* **Evidence Packages**: Bundle evidence artifacts with control mappings for audit submissions
## Control Testing
CaseBender includes a unified control testing module that works across all frameworks:
### Testing Capabilities
* **Automated Tests**: Configurable test procedures that run on schedule
* **Manual Tests**: Guided test procedures with evidence capture
* **Cross-Framework Mapping**: A single test can satisfy controls across multiple frameworks
* **Test Scheduling**: Calendar-based scheduling with reminders and escalation
* **Result Tracking**: Pass/fail/partial results with evidence attachment
### Testing Workflow
1. **Schedule**: Tests are scheduled based on framework requirements (quarterly, annually, etc.)
2. **Execute**: Automated tests run automatically; manual tests notify the assigned tester
3. **Evidence**: Test results and supporting evidence are captured automatically
4. **Review**: Results are reviewed and approved by the compliance team
5. **Report**: Test results feed into framework-specific compliance reports
## Compliance Training
Track and manage compliance training requirements:
* **Training Programs**: Define training requirements per framework and role
* **Assignment Management**: Automatically assign training based on user role and team
* **Completion Tracking**: Track completion rates, scores, and certification status
* **Compliance Matrix**: View training compliance across users, teams, and frameworks
* **Campaign Management**: Launch targeted training campaigns for new requirements
## Detailed Framework Documentation
Trust Service Criteria, evidence collection, attestation management
ISMS controls, risk management, internal audit, Statement of Applicability
Data subject rights, consent management, breach notification, cross-border transfers
CMMC, FedRAMP, HIPAA, PCI DSS, Export Control, EU AI Act
## Related Documentation
* [Audit Logging](/en/security/audit-logging) — The audit trail that provides compliance evidence
* [Data Protection](/en/security/data-protection) — Encryption and retention policies
* [Security Overview](/en/security/overview) — Platform security posture
# SOC2 Type II
Source: https://docs.casebender.com/en/security/compliance-soc2
How CaseBender helps you achieve and maintain SOC2 Type II compliance with automated evidence collection and control management.
## Overview
CaseBender provides comprehensive SOC2 Type II support, mapping platform capabilities to Trust Service Criteria and automating evidence collection for audit readiness.
SOC2 Type II evaluates the operating effectiveness of controls over a period of time (typically 6-12 months), making continuous evidence collection essential.
## Trust Service Criteria Coverage
### Security (Common Criteria)
| Control | Description | CaseBender Implementation |
| --------------- | --------------------------- | --------------------------------------------------------- |
| **CC1.1-CC1.5** | Control Environment | Organization management, team structure, role definitions |
| **CC2.1-CC2.3** | Communication & Information | Notification service, audit trail, dashboard reporting |
| **CC3.1-CC3.4** | Risk Assessment | Vulnerability management, risk scoring, threat detection |
| **CC4.1-CC4.2** | Monitoring Activities | UEBA, security monitoring, compliance dashboards |
| **CC5.1-CC5.3** | Control Activities | RBAC, MFA, encryption, input validation |
| **CC6.1-CC6.8** | Logical & Physical Access | Authentication, authorization, PAM, API security |
| **CC7.1-CC7.5** | System Operations | Audit logging, incident response, change management |
| **CC8.1** | Change Management | Version control, deployment pipelines, approval workflows |
| **CC9.1-CC9.2** | Risk Mitigation | SLA management, business continuity, disaster recovery |
### Availability
| Control | Description | CaseBender Implementation |
| -------- | ------------------- | -------------------------------------------------------- |
| **A1.1** | Capacity Management | Resource monitoring, auto-scaling support, health checks |
| **A1.2** | Recovery Procedures | Backup management, disaster recovery, data retention |
| **A1.3** | Recovery Testing | Backup verification, failover testing documentation |
### Confidentiality
| Control | Description | CaseBender Implementation |
| -------- | ----------------------------- | ---------------------------------------------------- |
| **C1.1** | Confidential Information | Data classification, TLP system, access controls |
| **C1.2** | Disposal of Confidential Info | Data retention policies, secure deletion, legal hold |
## Evidence Collection
### Automated Collectors
CaseBender includes automated evidence collectors that gather compliance artifacts without manual effort:
* **Access Control Evidence**: User lists, role assignments, permission matrices, MFA enrollment status
* **Audit Log Evidence**: Authentication events, authorization decisions, data access logs, configuration changes
* **Change Management Evidence**: Deployment history, code review records, approval workflows
* **Encryption Evidence**: Encryption configuration, key rotation history, TLS certificate status
* **Monitoring Evidence**: Alert history, incident response records, UEBA anomaly reports
### Collection Schedule
| Evidence Type | Frequency | Retention |
| ------------------------ | --------- | --------- |
| Access reviews | Quarterly | 3 years |
| Audit log samples | Monthly | 3 years |
| Configuration snapshots | Monthly | 3 years |
| Vulnerability scans | Weekly | 3 years |
| Penetration test results | Annually | 3 years |
| Training records | Quarterly | 3 years |
### Evidence Review Workflow
1. **Collection**: Automated collectors gather evidence on schedule
2. **Review**: Compliance team reviews collected evidence for completeness
3. **Approval**: Evidence is approved and tagged with the relevant control
4. **Storage**: Approved evidence is stored with tamper-evident integrity protection
5. **Retrieval**: Evidence is readily available for auditor review
## Audit Period Management
### Audit Periods
* Define audit periods with start and end dates
* Track evidence collection progress per period
* Monitor control effectiveness across the audit window
* Generate period-specific compliance reports
### Gap Analysis
CaseBender identifies gaps in your SOC2 compliance:
* Controls without sufficient evidence
* Controls with outdated evidence
* Controls that have not been tested within the required timeframe
* New controls introduced by TSC updates that need implementation
### Attestation Management
* Track attestation status per control
* Record control owner attestations
* Manage exception and remediation workflows
* Generate attestation reports for auditors
## Reporting
### Audit Reports
Generate comprehensive reports for your auditors:
* **Control Matrix**: Complete mapping of TSC controls to CaseBender implementations
* **Evidence Package**: Bundled evidence artifacts organized by control
* **Gap Report**: Outstanding gaps with remediation plans and timelines
* **Testing Results**: Control test results with pass/fail status and evidence
### Continuous Monitoring
Between formal audits, CaseBender provides continuous compliance monitoring:
* Real-time compliance score tracking
* Alert on control degradation
* Automated evidence collection ensures no gaps accumulate
* Dashboard showing audit readiness at any point in time
## Related Documentation
* [Compliance Overview](/en/security/compliance-overview) — All supported frameworks
* [Audit Logging](/en/security/audit-logging) — The audit trail powering SOC2 evidence
* [Access Control](/en/security/access-control) — RBAC and PAM controls
# Data Protection
Source: https://docs.casebender.com/en/security/data-protection
How CaseBender protects your data with encryption, classification, secrets management, and retention policies.
## Encryption
### Data at Rest
All data stored by CaseBender is encrypted at rest:
* **Database**: PostgreSQL Transparent Data Encryption (TDE) or filesystem-level encryption (dm-crypt/LUKS)
* **Field-Level Encryption**: Sensitive fields (API keys, integration credentials, PII) are encrypted at the application level using AES-256-GCM before storage
* **Key Versioning**: Encryption keys are versioned, allowing rotation without re-encrypting all data immediately
* **Backup Encryption**: Database backups inherit encryption from the underlying storage
### Data in Transit
All network communication is encrypted:
* **External Traffic**: TLS 1.3 required (TLS 1.2 minimum with AEAD cipher suites only)
* **Inter-Service**: Mutual TLS or HMAC-authenticated channels
* **Database Connections**: SSL/TLS with certificate verification
* **Redis Connections**: TLS with AUTH
* **Elasticsearch**: API key authentication over TLS
### Encryption Key Rotation
CaseBender supports automated encryption key rotation without downtime:
* New key versions are created and activated automatically on schedule
* Existing data continues to decrypt with the previous key version
* Background re-encryption progressively migrates data to the new key
* Progress tracking shows re-encryption status across all encrypted fields
* Old key versions are retained until all data is migrated, then securely destroyed
## Data Classification
CaseBender includes an automatic data classification engine that categorizes data based on sensitivity:
### Classification Levels
| Level | Description | Handling Requirements |
| ---------------- | ------------------------------------------------------------------ | ---------------------------------------------------------------------------- |
| **Restricted** | Highly sensitive data (credentials, PII, threat actor attribution) | Field-level encryption, strict access control, audit logging on every access |
| **Confidential** | Internal security data (case details, investigation notes) | Encrypted storage, role-based access, audit logging |
| **Internal** | Operational data (metrics, team assignments, workflow configs) | Standard access controls, periodic review |
| **Public** | Non-sensitive data (published CVEs, public advisories) | No special handling required |
### Automatic Classification
* **Rule Engine**: Configurable rules that classify entities based on content patterns, source, severity, and TLP level
* **Pattern Detection**: Scans for PII patterns (SSN, credit card numbers, email addresses) and auto-classifies accordingly
* **TLP Mapping**: TLP classifications automatically map to data classification levels
* **Propagation**: Classification levels propagate from parent to child entities (case to alerts, alerts to observables)
* **Review Workflow**: Classification changes above a threshold require human review and approval
## Secrets Management
CaseBender provides a centralized secrets management system with provider abstraction, so your deployment can use whichever secrets backend your organization standardizes on.
### Supported Providers
| Provider | Use Case | Features |
| ------------------------- | ------------------------------- | ------------------------------------------------ |
| **Environment Variables** | Development, simple deployments | Zero dependencies, easy setup |
| **HashiCorp Vault** | Enterprise on-premise | Dynamic secrets, lease management, audit logging |
| **AWS Secrets Manager** | AWS deployments | Automatic rotation, cross-region replication |
| **Azure Key Vault** | Azure deployments | HSM-backed keys, managed identity integration |
| **GCP Secret Manager** | Google Cloud deployments | IAM integration, automatic replication |
| **Kubernetes Secrets** | Kubernetes deployments | Native K8s integration, RBAC-controlled |
### Secrets Security Features
* **Audit Logging**: Every secret access, creation, update, and deletion is logged with actor identity and timestamp
* **Rotation Scheduling**: Automated rotation policies with configurable intervals per secret
* **Circuit Breaker**: If a secrets provider becomes unavailable, the system gracefully degrades with cached values and alerts operators
* **Retry with Backoff**: Transient failures are retried with exponential backoff before triggering the circuit breaker
* **Health Monitoring**: Continuous health checks on secrets providers with alerting on degradation
## Data Retention
CaseBender supports configurable data retention policies that comply with multiple regulatory frameworks:
### Jurisdiction-Aware Retention
Retention policies are configurable per jurisdiction to meet local regulatory requirements:
| Framework | Minimum Retention | Right to Erasure | Legal Basis Required |
| ------------------ | ------------------------------- | ---------------- | -------------------- |
| **GDPR** | No minimum (purpose limitation) | Yes (Article 17) | Yes |
| **SOC2** | 1 year | No | No |
| **HIPAA** | 6 years | No | No |
| **PCI DSS** | 1 year | No | No |
| **SEC Rule 17a-4** | 3-7 years | No | No |
| **CMMC** | 3 years | No | No |
### Retention Features
* **Policy Engine**: Define retention periods by entity type, classification level, and jurisdiction
* **Legal Hold Integration**: Entities under legal hold are exempt from automated deletion regardless of retention policy
* **Erasure Requests**: GDPR-compliant right to erasure with verification and audit trail
* **Impact Preview**: Before executing retention, preview exactly which entities will be affected
* **Automated Execution**: Scheduled retention jobs with full audit logging of every deletion
## Related Documentation
* [Security Architecture](/en/security/architecture) — Zero Trust design and service isolation
* [Authentication](/en/security/authentication) — How access to data is controlled
* [Compliance: GDPR](/en/security/compliance-gdpr) — GDPR-specific data protection features
* [Audit Logging](/en/security/audit-logging) — How data access is tracked
# Hardening Guide
Source: https://docs.casebender.com/en/security/hardening-guide
Recommendations for hardening your CaseBender deployment including TLS, database, Redis, container, and monitoring configuration.
## Overview
CaseBender ships with secure defaults, but your deployment environment requires additional hardening. This guide provides recommendations for securing the infrastructure surrounding CaseBender.
This guide covers infrastructure hardening. CaseBender's application-level security (encryption, RBAC, audit logging) is configured within the application itself. See the relevant security documentation pages for application configuration.
## TLS Configuration
### Reverse Proxy
CaseBender should be deployed behind a reverse proxy (Nginx, Caddy, Traefik, or cloud load balancer) that terminates TLS:
**Recommended TLS Settings:**
| Setting | Value |
| ------------------- | -------------------------------------------------- |
| Minimum TLS Version | TLS 1.2 (TLS 1.3 preferred) |
| Cipher Suites | AEAD ciphers only (AES-256-GCM, ChaCha20-Poly1305) |
| HSTS | Enabled with `max-age=31536000; includeSubDomains` |
| OCSP Stapling | Enabled |
| Certificate Type | RSA 2048+ or ECDSA P-256+ |
**Nginx Example:**
```nginx theme={null}
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305;
ssl_prefer_server_ciphers on;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
```
### Certificate Management
* Use certificates from a trusted Certificate Authority (Let's Encrypt, DigiCert, etc.)
* Automate certificate renewal (certbot, cert-manager)
* Monitor certificate expiration with alerting (minimum 30 days before expiry)
* Use separate certificates for internal services if implementing mutual TLS
## Database Security
### PostgreSQL Hardening
| Setting | Recommendation |
| ------------------- | ------------------------------------------------------------------------------- |
| **Authentication** | `scram-sha-256` (not `md5` or `trust`) |
| **SSL** | Required for all connections (`ssl = on`, `ssl_min_protocol_version = TLSv1.2`) |
| **Network** | Listen only on private network interfaces |
| **Firewall** | Allow connections only from CaseBender application services |
| **Superuser** | Disable remote superuser access |
| **Logging** | Enable `log_connections`, `log_disconnections`, `log_statement = 'ddl'` |
| **Password Policy** | Minimum 16 characters, rotated quarterly |
**pg\_hba.conf Example:**
```
# Reject all by default
host all all 0.0.0.0/0 reject
# Allow CaseBender services from private network only
hostssl casebender casebender_app 10.0.1.0/24 scram-sha-256
```
### Backup Security
* Encrypt backups at rest (AES-256)
* Store backups in a separate location from the primary database
* Test backup restoration quarterly
* Retain backups according to your compliance requirements (minimum 30 days)
* Monitor backup job success/failure with alerting
## Redis Security
### Redis Hardening
| Setting | Recommendation |
| ---------------------- | ------------------------------------------------------------- |
| **Authentication** | `requirepass` with a strong password (32+ characters) |
| **TLS** | Enable TLS for all connections (`tls-port` instead of `port`) |
| **Network** | Bind to private network interface only (`bind 10.0.1.x`) |
| **Dangerous Commands** | Rename or disable `FLUSHALL`, `FLUSHDB`, `CONFIG`, `DEBUG` |
| **Max Memory** | Set `maxmemory` with `maxmemory-policy allkeys-lru` |
| **Persistence** | Enable AOF persistence for durability |
**redis.conf Example:**
```
bind 10.0.1.5
port 0
tls-port 6379
tls-cert-file /etc/redis/tls/redis.crt
tls-key-file /etc/redis/tls/redis.key
tls-ca-cert-file /etc/redis/tls/ca.crt
requirepass YOUR_STRONG_PASSWORD_HERE
rename-command FLUSHALL ""
rename-command FLUSHDB ""
rename-command CONFIG "CONFIG_b4c2e8f1"
maxmemory 2gb
maxmemory-policy allkeys-lru
```
## Container Security
### Runtime Hardening
If deploying CaseBender with Docker or Kubernetes:
**Docker Compose:**
```yaml theme={null}
services:
web:
image: casebender/web:latest
read_only: true
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
tmpfs:
- /tmp
deploy:
resources:
limits:
cpus: '2.0'
memory: 4G
reservations:
cpus: '0.5'
memory: 1G
```
**Kubernetes:**
```yaml theme={null}
securityContext:
runAsNonRoot: true
runAsUser: 1001
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
resources:
limits:
cpu: "2"
memory: "4Gi"
requests:
cpu: "500m"
memory: "1Gi"
```
### Image Verification
Before deploying, verify container image signatures:
```bash theme={null}
# Verify image signature
cosign verify \
--certificate-identity-regexp="github.com/casebender" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com" \
REGISTRY/casebender/web:TAG
# Verify SBOM attestation
cosign verify-attestation \
--type cyclonedx \
--certificate-identity-regexp="github.com/casebender" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com" \
REGISTRY/casebender/web:TAG
```
## Network Security
### Firewall Rules
| Source | Destination | Port | Protocol | Purpose |
| ------------- | ----------------- | -------------- | -------- | ------------------- |
| Internet | Load Balancer | 443 | HTTPS | User access |
| Load Balancer | Web/API/Ingestion | 3000/4000/4100 | HTTP | Application traffic |
| App Services | PostgreSQL | 5432 | TCP/TLS | Database |
| App Services | Redis | 6379 | TCP/TLS | Cache/Queue |
| App Services | Elasticsearch | 9200 | HTTPS | Search |
| App Services | SIEM | Varies | TCP/TLS | Audit forwarding |
### Recommendations
* Block all inbound traffic except port 443
* Use private networking for all inter-service communication
* Implement network segmentation between application and data tiers
* Enable network flow logging for forensic analysis
* Consider a Web Application Firewall (WAF) in front of the load balancer
## Monitoring
### Health Check Endpoints
CaseBender exposes health check endpoints for monitoring:
| Endpoint | Purpose | Response |
| ----------------------- | --------------------------------------- | -------------------------- |
| `/api/health/liveness` | Is the service running? | 200 OK / 503 |
| `/api/health/readiness` | Is the service ready to accept traffic? | 200 OK / 503 |
| `/api/health/detailed` | Detailed health with dependency status | JSON with component health |
### Recommended Monitoring
| Metric | Alert Threshold | Tool |
| --------------------- | ---------------------- | ------------------------------- |
| Health check failures | 3 consecutive failures | Prometheus, Datadog, CloudWatch |
| Response time (P95) | > 2 seconds | APM tool |
| Error rate (5xx) | > 1% of requests | Log aggregation |
| CPU utilization | > 80% sustained | Infrastructure monitoring |
| Memory utilization | > 85% | Infrastructure monitoring |
| Disk usage | > 80% | Infrastructure monitoring |
| Certificate expiry | \< 30 days | Certificate monitoring |
| Backup age | > 24 hours | Backup monitoring |
### Log Aggregation
Collect and centralize logs from all CaseBender services:
* Application logs (structured JSON)
* Access logs (reverse proxy)
* Database logs (PostgreSQL)
* Redis logs
* Container runtime logs
Use a log aggregation solution (ELK, Loki, Datadog, Splunk) to centralize, search, and alert on log data.
## Backup and Recovery
### Backup Strategy
| Component | Frequency | Retention | Method |
| ------------- | ------------------------------- | --------- | --------------------------- |
| PostgreSQL | Daily (full) + Continuous (WAL) | 30 days | pg\_dump + WAL archiving |
| Redis | Hourly (AOF) | 7 days | AOF persistence + snapshots |
| Elasticsearch | Daily | 14 days | Snapshot and restore |
| Configuration | On change | 90 days | Version control |
### Recovery Targets
| Metric | Target | Description |
| ---------------------------------- | ---------- | ---------------------------- |
| **RPO** (Recovery Point Objective) | \< 1 hour | Maximum acceptable data loss |
| **RTO** (Recovery Time Objective) | \< 4 hours | Maximum acceptable downtime |
### Recovery Testing
* Test database restoration quarterly
* Test full environment recovery annually
* Document recovery procedures and keep them updated
* Conduct tabletop exercises for disaster scenarios
## Related Documentation
* [Security Architecture](/en/security/architecture) — Platform security design
* [Supply Chain Security](/en/security/supply-chain) — Container image verification
* [Deployment Overview](/en/deployment/overview) — Platform deployment guides
# Security Overview
Source: https://docs.casebender.com/en/security/overview
CaseBender is built for security teams and secured like one. Explore our enterprise-grade security controls, compliance frameworks, and transparent build pipeline.
## Built for Security Teams, Secured Like One
CaseBender is an on-premise case management platform purpose-built for Security Operations Centers. We understand that the tools security teams rely on must meet the same rigorous standards they enforce across their organizations.
### Live Pipeline Status
Every code change to CaseBender passes through automated security gates before it reaches a release. These badges reflect real-time CI/CD status from our build pipeline:
| Check | Status | What It Covers |
| --------------- | ---------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| Security Scan |  | Gitleaks, Trivy, Semgrep SAST, ESLint Security, OWASP ZAP, dependency review, license compliance, SBOM generation |
| Supply Chain |  | Reproducible build verification, lockfile integrity, dependency pinning, image verification |
| Image Signing |  | Cosign keyless signing for all container images, SBOM attestation |
| SLSA Provenance |  | SLSA Level 2+ build provenance generation and signing |
| Accessibility |  | WCAG 2.1 AA, Section 508, ADA Title III compliance |
These badges are live and link directly to our CI/CD pipeline. They update automatically with every build.
## Security by the Numbers
From Zero Trust architecture to DDoS protection, covering SEC-001 through SEC-020
SOC2, ISO 27001, GDPR, CMMC, FedRAMP, HIPAA, PCI DSS, and more
Automated scanning on every commit: SAST, DAST, SCA, secrets, licenses, containers
Your data never leaves your infrastructure. No telemetry, no cloud dependencies
Every container image is signed with Sigstore. Every build has SLSA provenance
Each service image is individually scanned, signed, and attested before release
## Security Principles
### Defense in Depth
CaseBender implements multiple layers of security controls. No single control is relied upon in isolation:
* **Perimeter**: Rate limiting, DDoS detection, input validation, SSRF prevention
* **Authentication**: MFA (TOTP + WebAuthn/FIDO2), SSO (SAML 2.0), step-up authentication
* **Authorization**: RBAC, TLP-based access control, privileged access management
* **Data**: Encryption at rest (AES-256) and in transit (TLS 1.3), field-level encryption, data classification
* **Monitoring**: UEBA behavioral analytics, insider threat detection, unified audit trail, SIEM forwarding
* **Supply Chain**: Signed images, SBOM, SLSA provenance, dependency scanning, reproducible builds
### Zero Trust Architecture
Every request is verified regardless of origin. CaseBender implements:
* Device trust assessment with risk scoring
* Mutual service authentication (HMAC) between microservices
* Step-up authentication for sensitive operations
* Continuous session validation
* No implicit trust between services
### On-Premise Advantage
As an on-premise platform, CaseBender provides inherent security benefits:
* **Data Sovereignty**: Customer data stays within your infrastructure boundary
* **Network Control**: You control all ingress and egress
* **Air-Gap Support**: Deployable in fully isolated environments
* **No Vendor Access**: CaseBender has zero access to your running instance or data
* **Compliance Simplification**: Your data classification and retention policies apply directly
## Explore Security Documentation
Zero Trust design, service mesh, network segmentation, and multi-tenant isolation
Encryption, data classification, TLP system, secrets management, and retention policies
MFA, SSO, account lockout, step-up authentication, and WebAuthn/FIDO2
RBAC, privileged access management, cross-team visibility, and API security
UEBA, insider threat detection, DDoS protection, and SIEM integration
SOC2, ISO 27001, GDPR, CMMC, FedRAMP, HIPAA, PCI DSS, and more
Dependency management, container signing, SBOM, SLSA provenance
SAST, DAST, vulnerability management, penetration testing, license compliance
Unified audit trail, integrity verification, legal hold, e-discovery
Deployment hardening, database security, container security, monitoring
## Responsible Disclosure
If you discover a security vulnerability in CaseBender, please report it responsibly to [security@casebender.com](mailto:security@casebender.com). We take all reports seriously and will respond within 24 hours.
# Supply Chain Security
Source: https://docs.casebender.com/en/security/supply-chain
How CaseBender secures its build pipeline with dependency management, container signing, SBOM generation, and SLSA provenance.
## Overview
CaseBender's supply chain security ensures that every artifact you deploy has been built from verified source code, scanned for vulnerabilities, signed cryptographically, and attested with provenance. These controls run automatically in our CI/CD pipeline — not as optional steps, but as mandatory gates that block releases.
### Live Pipeline Status
| Pipeline | Status | Runs On |
| ------------------- | --------------------------------------------------------------------------------------------------------------------- | ----------------------------- |
| Security Scan |  | Every PR and push to main |
| Supply Chain Verify |  | Every PR and push to main |
| Image Signing |  | Every push to main/production |
| SLSA Provenance |  | Every push to main/production |
## Dependency Management
### Version Pinning
All dependencies are pinned to exact versions to prevent supply chain attacks via version drift:
* **`save-exact=true`** in `.npmrc` ensures every `pnpm add` pins to the exact version
* **`strict-peer-dependencies=true`** catches incompatible peer dependency versions
* **`pnpm install --frozen-lockfile`** in all Dockerfiles ensures builds use exactly the versions in the lockfile
* **Node.js version pinned** via `.nvmrc` and `.node-version` (Node.js 20.x)
* **pnpm version pinned** in Dockerfiles to prevent tool-level supply chain attacks
### Automated Dependency Updates
[Dependabot](https://docs.github.com/en/code-security/dependabot) monitors for updates across three ecosystems:
| Ecosystem | Schedule | Scope |
| ------------------ | ------------------ | ---------------------------------------------------------- |
| **npm** | Weekly (Monday) | Production deps, dev deps, OpenTelemetry, Prisma (grouped) |
| **Docker** | Weekly (Tuesday) | Base images for all 7 services |
| **GitHub Actions** | Weekly (Wednesday) | All CI/CD workflow action versions |
Dependabot PRs are:
* Automatically labeled with `dependencies` and `security`
* Blocked from merging if they introduce HIGH or CRITICAL vulnerabilities
* Reviewed by the security team before merge
### Dependency Review
Every pull request is automatically checked for:
* New dependencies with known vulnerabilities (HIGH/CRITICAL blocked)
* Dependencies with forbidden licenses (copyleft licenses blocked)
* Dependencies with no license (flagged for review)
* Pre-release dependencies (documented and tracked)
### Approved Component Registry
CaseBender maintains a documented registry of approved third-party components organized by risk tier:
| Tier | Risk Level | Examples | Review Frequency |
| ---------- | ---------- | --------------------------------------- | --------------------- |
| **Tier 1** | Critical | next-auth, prisma, bcrypt, jose | Every update reviewed |
| **Tier 2** | High | tRPC, zod, bullmq, ioredis | Monthly review |
| **Tier 3** | Medium | shadcn/ui, lucide-react, tailwindcss | Quarterly review |
| **Tier 4** | Low | eslint, prettier, typescript (dev-only) | Annual review |
## Container Security
### Build Hardening
Every CaseBender container image follows security best practices:
```
Multi-Stage Build → Non-Root User → Alpine Base → Pinned Versions → Frozen Lockfile → No Secrets
```
* **Multi-stage builds**: Build dependencies (compilers, dev tools) are excluded from production images
* **Non-root users**: Each service runs as a dedicated non-root user inside the container
* **Alpine Linux**: Minimal base images reduce attack surface
* **Pinned tool versions**: System packages and global tools are version-pinned
* **No embedded secrets**: All secrets are injected at runtime
### Container Scanning
Every container image is scanned with [Trivy](https://trivy.dev/) for:
* **OS vulnerabilities**: CVEs in Alpine packages
* **Application vulnerabilities**: CVEs in Node.js dependencies
* **Misconfigurations**: Dockerfile best practice violations
* **Secrets**: Embedded credentials or API keys
Scans run on every PR and block merges if CRITICAL or HIGH vulnerabilities are found.
## Image Signing
All 7 CaseBender container images are cryptographically signed using [Cosign](https://docs.sigstore.dev/cosign/overview/) with keyless signing via [Sigstore](https://www.sigstore.dev/):
### Signed Images
| Image | Registry |
| ------------------------------- | ------------------------ |
| `casebender/web` | Google Artifact Registry |
| `casebender/api` | Google Artifact Registry |
| `casebender/ingestion` | Google Artifact Registry |
| `casebender/worker` | Google Artifact Registry |
| `casebender/workflow-processor` | Google Artifact Registry |
| `casebender/misp-processor` | Google Artifact Registry |
| `casebender/search-sync` | Google Artifact Registry |
### Verification
Before deployment, our CI/CD pipeline verifies:
1. **Signature Verification**: Cosign verifies the image signature against the Sigstore transparency log
2. **SBOM Attestation**: Verifies that a signed SBOM is attached to the image
3. **Vulnerability Scan**: Final Trivy scan for CRITICAL vulnerabilities
4. **Provenance Check**: Verifies SLSA provenance attestation exists
You can verify any CaseBender image signature yourself using:
```bash theme={null}
cosign verify --certificate-identity-regexp="github.com/casebender" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com" \
REGISTRY/casebender/web:TAG
```
## SBOM (Software Bill of Materials)
Every release includes a signed Software Bill of Materials in [CycloneDX](https://cyclonedx.org/) format:
* **Generated by**: Trivy SBOM scanner
* **Format**: CycloneDX JSON
* **Signed with**: Cosign (keyless via Sigstore)
* **Attached to**: Each container image as an attestation
* **Retention**: 3 years (aligned with compliance requirements)
The SBOM documents every component in the container image:
* Node.js runtime version
* All npm packages with exact versions
* Alpine Linux packages
* System libraries and their versions
## SLSA Provenance
CaseBender generates [SLSA](https://slsa.dev/) Level 2+ build provenance for every release:
### What Provenance Documents
| Field | Content |
| ---------------- | ------------------------------------------- |
| **Source** | Git commit SHA, repository URL, branch |
| **Builder** | GitHub Actions workflow, runner environment |
| **Build Config** | Workflow file path, trigger event |
| **Artifacts** | Container image digests for all 7 services |
| **Metadata** | Build timestamp, actor, invocation ID |
### Provenance Security
* Provenance documents are signed with Cosign (keyless via Sigstore)
* Signatures are verified after generation
* Provenance is retained for 3 years
* Provenance can be independently verified against the Sigstore transparency log
## Pre-Deployment Verification
Before any deployment, two verification scripts run as mandatory gates:
### Reproducible Build Verification
Checks that the build environment is consistent and secure:
* Lockfile integrity (`pnpm-lock.yaml` exists and is valid)
* Node.js version matches expected version (20.x)
* pnpm version matches expected version (9.15.0)
* `.npmrc` security settings are present (`save-exact`, `audit`)
* No suspicious postinstall scripts in dependencies
* Version pinning files (`.nvmrc`, `.node-version`) are present
### Image Verification
Checks that container images are authentic and safe:
* Cosign signature verification for each image
* SBOM attestation verification
* Trivy vulnerability scan (CRITICAL severity)
* Image provenance check
## Compliance Mapping
| Control | Framework | CaseBender Implementation |
| ---------------------------- | ----------- | ----------------------------------------------------------- |
| SR-3 Supply Chain Protection | CMMC | Dependency pinning, lockfile integrity, reproducible builds |
| SR-4 Provenance | CMMC | SLSA provenance, image signing, SBOM |
| SR-11 Component Authenticity | CMMC | Cosign signature verification, Sigstore transparency |
| SI-7 Software Integrity | NIST 800-53 | Image signing, SBOM attestation, build verification |
| CM-2 Baseline Configuration | NIST 800-53 | Pinned versions, frozen lockfiles, reproducible builds |
| CM-6 Configuration Settings | NIST 800-53 | `.npmrc` hardening, Dockerfile best practices |
## Related Documentation
* [Code Security](/en/security/code-security) — SAST, DAST, and vulnerability management
* [Security Overview](/en/security/overview) — Live pipeline status badges
* [Hardening Guide](/en/security/hardening-guide) — Deployment security recommendations
# AI Settings
Source: https://docs.casebender.com/en/settings/ai/introduction
Configure and manage AI providers to enable intelligent features in your CaseBender instance.
## Overview
The AI Settings section allows you to configure various AI providers to enhance your CaseBender experience with intelligent features. This includes setting up providers like OpenAI, Anthropic, and others to power features such as case analysis, content generation, and automated processing.
## Configuring AI Providers
### Step 1: Enable Provider
To start using an AI provider, locate the provider card in the dashboard and toggle the enable switch:
The configuration modal will appear where you can:
* Enter your API key
* Configure basic settings
* Set usage limits
* Define access permissions
### Step 2: Model Selection
After entering a valid API key, you'll see available models for the provider:
Configure model-specific settings:
* Select preferred models
* Set model-specific parameters
* Configure usage quotas
* Define model access permissions
### Step 3: Provider Configuration Complete
Once configured, the provider card will show its active status and configuration details:
The configured provider card displays:
* Active status
* Selected models
* Usage statistics
* Quick access to settings
## Available Providers
### OpenAI
* GPT-4 and GPT-3.5 models
* Text generation and analysis
* Code assistance
* Data extraction
### Anthropic
* Claude and Claude 2 models
* Advanced reasoning
* Document analysis
* Complex task handling
### Deepseek
* Deepseek-coder models
* Code generation and analysis
* Technical documentation
* Programming assistance
### Azure OpenAI
* Managed OpenAI services
* Enterprise security features
* Regional availability
* Dedicated resources
### Groq
* LPU inference
* Ultra-fast processing
* High-performance models
* Low-latency responses
### Google AI
* PaLM and Gemini models
* Multi-modal capabilities
* Advanced language understanding
* Enterprise-grade reliability
### xAI
* Grok models
* Real-time knowledge integration
* Conversational AI
* Context-aware responses
### Ollama
* Local model deployment
* Custom model support
* Offline processing
* Resource-efficient inference
## Best Practices
### Security
* Securely store API keys
* Regularly rotate credentials
* Monitor API usage
* Set appropriate access controls
### Cost Management
* Configure usage limits
* Monitor token consumption
* Set model-specific quotas
* Track usage patterns
### Performance
* Choose appropriate models
* Optimize prompt engineering
* Monitor response times
* Configure timeout settings
### Maintenance
* Regularly verify provider status
* Update API keys before expiration
* Monitor model availability
* Keep configurations current
## Features Enabled by AI
### Case Management
* Automated case analysis
* Content summarization
* Priority assessment
* Related case identification
### Document Processing
* Text extraction
* Document classification
* Content analysis
* Key information highlighting
### Workflow Automation
* Intelligent routing
* Content generation
* Decision support
* Pattern recognition
## Related Documentation
* [AI Features](../../cases/ai-features.mdx)
# Alert Statuses
Source: https://docs.casebender.com/en/settings/alert-statuses/introduction
Configure and manage custom alert statuses to track the lifecycle of alerts in your security operations.
## Overview
The Alert Statuses section allows you to create and manage custom status definitions for your alerts. This feature helps you track the progression of alerts through your security operations workflow, from initial detection to final resolution.
## Managing Alert Statuses
### Creating a New Status
Click the "Create" button to add a new alert status:
Configure the basic status information:
* Status name
* Description
* Color indicator
* Icon selection
* Category
### Configuring Status Details
Provide comprehensive configuration for your alert status:
Define detailed settings:
* Status behavior
* Automation rules
* Notification settings
* Access permissions
### Status Management
View and manage your configured alert statuses:
The status list displays:
* Status name and icon
* Description
* Category
* Creation date
* Last modified
* Actions
## Default Status Types
### New Alerts
* New
* Unassigned
* Assigned
* In Progress
### Investigation
* Under Investigation
* Needs Information
* Awaiting Response
* On Hold
### Resolution
* Resolved
* Closed
* False Positive
* Duplicate
### Escalation
* Escalated
* Critical
* Requires Attention
* Pending Review
## Status Configuration
### Visual Indicators
* Color coding
* Icon selection
* Status badges
* Priority markers
### Behavior Settings
* Auto-transition rules
* Time-based triggers
* Required fields
* Status dependencies
### Access Control
* Role-based access
* Team permissions
* Status restrictions
* Modification rights
## Best Practices
### Status Design
* Use clear, descriptive names
* Maintain consistent naming
* Choose intuitive colors
* Select appropriate icons
### Workflow Integration
* Define logical progression
* Set up automation rules
* Configure notifications
* Enable tracking
### Organization
* Group related statuses
* Define clear categories
* Set proper ordering
* Maintain hierarchy
### Maintenance
* Review status usage
* Update as needed
* Remove unused statuses
* Document changes
## Using Alert Statuses
### In Alert Management
* Track alert lifecycle
* Monitor progress
* Manage workload
* Measure response time
### In Reporting
* Status distribution
* Resolution metrics
* Team performance
* Response analytics
### In Automation
* Status-based triggers
* Automatic updates
* Notification rules
* Workflow automation
# Attack Patterns
Source: https://docs.casebender.com/en/settings/attack-patterns/introduction
Browse and manage MITRE ATT&CK patterns to enhance your threat detection and response capabilities.
## Overview
The Attack Patterns section provides access to a comprehensive library of MITRE ATT\&CK patterns, enabling you to understand, track, and defend against various cyber attack techniques. This knowledge base helps in identifying, categorizing, and responding to security threats effectively.
## Understanding Attack Patterns
### Pattern Categories
* Initial Access
* Execution
* Persistence
* Privilege Escalation
* Defense Evasion
* Credential Access
* Discovery
* Lateral Movement
* Collection
* Command and Control
* Exfiltration
* Impact
### Pattern Information
Each attack pattern entry includes:
* Technique ID (e.g., T1234)
* Technique Name
* Tactic Category
* Description
* Sub-techniques
* Detection Methods
* Mitigation Strategies
## Using Attack Patterns
### Threat Analysis
* Identify attack techniques
* Map threat actor behaviors
* Analyze attack chains
* Assess risk levels
### Incident Response
* Classify incidents
* Guide investigation
* Determine scope
* Plan remediation
### Threat Hunting
* Create hunt hypotheses
* Define search patterns
* Identify indicators
* Track progression
## Integration Features
### Case Management
* Link patterns to cases
* Document observed techniques
* Track attack progression
* Map incident timeline
### Threat Intelligence
* Correlate with known threats
* Map actor behaviors
* Identify emerging patterns
* Share intelligence
### Reporting
* Generate attack summaries
* Create pattern analytics
* Track pattern frequency
* Measure effectiveness
## Best Practices
### Pattern Analysis
* Review pattern details
* Understand prerequisites
* Identify dependencies
* Map related techniques
### Implementation
* Document observed patterns
* Link to incidents
* Track effectiveness
* Update procedures
### Maintenance
* Keep patterns current
* Review classifications
* Update documentation
* Monitor trends
### Team Training
* Share pattern knowledge
* Practice identification
* Review case studies
* Update procedures
## MITRE ATT\&CK Framework
### Framework Overview
* Enterprise Matrix
* Mobile Matrix
* ICS Matrix
* Cloud Matrix
### Tactics Categories
* Why attackers use them
* Common implementations
* Detection strategies
* Mitigation approaches
### Techniques & Sub-techniques
* Detailed descriptions
* Implementation examples
* Detection methods
* Mitigation strategies
## Related Documentation
* [Case Management](../../cases/introduction.mdx)
# Branding
Source: https://docs.casebender.com/en/settings/branding/introduction
Customize the look and feel of your CaseBender instance with your organization's branding elements.
## Overview
The Branding section allows you to customize the visual appearance of your CaseBender instance to match your organization's brand identity. You can configure colors, logos, and other visual elements to create a consistent and professional look across your security operations platform.
## Brand Elements
### Primary Colors
Configure your organization's primary color scheme:
Customize the following color elements:
* Primary brand color
* Secondary colors
* Accent colors
* Background colors
* Text colors
## Customization Options
### Logo Settings
* Upload organization logo
* Set logo dimensions
* Configure placement
* Define visibility rules
* Dark/light mode variants
### Color Scheme
* Primary colors
* Secondary palette
* System status colors
* Alert level indicators
* Background gradients
### Typography
* Font family selection
* Text sizes
* Font weights
* Line heights
* Letter spacing
### UI Elements
* Button styles
* Form elements
* Card designs
* Navigation items
* Modal windows
## Theme Configuration
### Light Mode
* Background colors
* Text colors
* UI element colors
* Contrast settings
* Accessibility options
### Dark Mode
* Dark theme colors
* Text visibility
* Element contrast
* Shadow effects
* Accent highlights
### System Elements
* Navigation bar
* Sidebar
* Headers
* Footers
* Action buttons
## Best Practices
### Brand Consistency
* Follow brand guidelines
* Maintain color harmony
* Ensure readability
* Consider accessibility
* Test across devices
### Visual Hierarchy
* Emphasize important elements
* Create clear contrast
* Use consistent spacing
* Implement proper scaling
* Maintain balance
### Accessibility
* Color contrast ratios
* Text readability
* Screen reader support
* Keyboard navigation
* Focus indicators
### Performance
* Optimize image sizes
* Minimize CSS
* Cache resources
* Load time considerations
* Responsive design
## Implementation Guide
### Basic Setup
1. Upload brand assets
2. Configure primary colors
3. Set typography
4. Adjust UI elements
5. Test appearance
### Advanced Configuration
1. Custom CSS rules
2. Component overrides
3. Theme variations
4. Responsive adjustments
5. Animation settings
### Testing
1. Cross-browser testing
2. Device compatibility
3. Accessibility validation
4. Performance checks
5. User feedback
# Case Statuses
Source: https://docs.casebender.com/en/settings/case-statuses/introduction
Configure and manage custom case statuses to track the lifecycle of cases in your security operations.
## Overview
The Case Statuses section enables you to create and manage custom status definitions for your cases. This feature helps you track the progression of cases through your incident response and investigation workflow, ensuring consistent case management across your organization.
## Managing Case Statuses
### Creating a New Status
Click the "Create" button to add a new case status:
Configure the basic status information:
* Status name
* Description
* Color indicator
* Icon selection
* Category/Phase
### Configuring Status Details
Provide comprehensive configuration for your case status:
Define detailed settings:
* Status behavior
* Workflow rules
* Required fields
* Team permissions
### Status Management
View and manage your configured case statuses:
The status list displays:
* Status name and icon
* Description
* Phase/Category
* Creation date
* Last modified
* Actions
## Default Status Types
### Initial Phase
* New
* Opened
* Assigned
* Triaged
### Investigation Phase
* Under Investigation
* Evidence Collection
* Analysis in Progress
* Pending Information
### Action Phase
* Containment
* Eradication
* Recovery
* Remediation
### Closure Phase
* Resolved
* Closed
* Archived
* Reopened
## Status Configuration
### Visual Elements
* Status colors
* Icon selection
* Phase indicators
* Priority badges
### Workflow Rules
* Status transitions
* Required actions
* Time limits
* Dependencies
### Field Requirements
* Mandatory fields
* Optional information
* Documentation needs
* Approval requirements
## Best Practices
### Status Design
* Clear naming conventions
* Logical progression
* Consistent terminology
* Intuitive organization
### Process Integration
* Align with procedures
* Define clear transitions
* Set completion criteria
* Enable tracking
### Team Collaboration
* Role assignments
* Handoff procedures
* Communication rules
* Responsibility matrix
### Quality Control
* Regular reviews
* Status audits
* Process validation
* Effectiveness metrics
## Using Case Statuses
### In Case Management
* Track investigation progress
* Monitor response actions
* Manage resources
* Ensure compliance
### In Workflow Automation
* Status-based triggers
* Automatic assignments
* Notification rules
* SLA tracking
### In Reporting
* Case metrics
* Resolution times
* Team performance
* Trend analysis
## Related Documentation
* [Case Management](../../cases/introduction.mdx)
# Custom Fields
Source: https://docs.casebender.com/en/settings/custom-fields/introduction
Create and manage custom fields to extend your case management capabilities in CaseBender.
## Overview
The Custom Fields section allows you to create and manage additional fields that can be used across your cases and tasks. This feature enables you to customize your data collection and organization according to your specific needs.
## Creating Custom Fields
### Step 1: Initialize Creation
Click the "Create" button to start creating a new custom field:
Fill out the basic information:
* Field name
* Description
* Category
* Required status
* Visibility settings
### Step 2: Select Field Type
Choose the appropriate field type for your data:
Available field types include:
* Text (Single line)
* Text Area (Multi-line)
* Number
* Date
* Select (Single choice)
* Multi-select
* Checkbox
* Radio buttons
* URL
* Email
* Phone number
### Step 3: Field Configuration Complete
After creation, the field will appear in the custom fields table:
The table displays:
* Field name
* Type
* Category
* Required status
* Creation date
* Last modified date
* Actions
## Field Types and Use Cases
### Text Fields
* Single line: Short text responses
* Text area: Detailed descriptions
* Rich text: Formatted content
### Numeric Fields
* Numbers: Quantities, measurements
* Currency: Financial values
* Percentage: Ratios, completion rates
### Selection Fields
* Dropdown: Single choice from options
* Multi-select: Multiple choices
* Radio buttons: Exclusive choices
* Checkboxes: Yes/No options
### Special Fields
* Date/Time: Temporal information
* URL: Web links
* Email: Contact information
* Phone: Contact numbers
## Best Practices
### Field Design
* Use clear, descriptive names
* Provide helpful descriptions
* Choose appropriate field types
* Set sensible default values
### Organization
* Group related fields
* Maintain consistent naming
* Use categories effectively
* Consider field order
### Validation
* Set appropriate constraints
* Define required fields
* Configure format validation
* Test field behavior
### Maintenance
* Review field usage
* Update obsolete fields
* Document changes
* Monitor performance impact
## Using Custom Fields
### In Cases
* Add to case forms
* Use in case views
* Include in reports
* Filter and sort
### In Tasks
* Task creation forms
* Task details
* Progress tracking
* Completion criteria
### In Reports
* Data analysis
* Custom metrics
* Export options
* Dashboard integration
## Related Documentation
* [Case Management](../../cases/introduction.mdx)
* [Task Management](../../tasks/introduction.mdx)
# Integrations
Source: https://docs.casebender.com/en/settings/integrations/introduction
Configure and manage integrations with external services and systems in your CaseBender instance.
## Overview
The Integration Settings section allows you to manage and create integrations with various external services to enhance your CaseBender workflow. This guide will walk you through the process of setting up new integrations.
## Creating a New Integration
### Step 1: Select Integration Type
From the dashboard, click the "Create" button to see available integration options:
### Step 2: Basic Configuration
After selecting an integration type, you'll be presented with the integration configuration form:
Fill out the required information such as:
* Integration name
* Description
* Basic configuration options
* Connection details
### Step 3: Advanced Settings
Configure additional settings specific to your integration type:
### Step 4: Organization Settings
Specify which organizations can access this integration:
* Select applicable organizations
* Set organization-specific configurations
* Define access levels and permissions
### Step 5: Final Configuration
After clicking the Continue button, complete the final configuration steps:
* Configure advanced features
* Set up authentication details
* Review and verify settings
* Test the connection
## Best Practices
### Setting Up Integrations
* Choose meaningful names for easy identification
* Provide detailed descriptions for future reference
* Test connections before finalizing
* Document custom configurations
### Security Considerations
* Use secure credentials
* Implement proper access controls
* Regular security audits
* Monitor integration usage
### Maintenance
* Regularly verify integration status
* Update configurations as needed
* Monitor performance metrics
* Keep documentation current
# Microsoft Defender XDR
Source: https://docs.casebender.com/en/settings/integrations/microsoft-defender
Bi-directional integration between CaseBender and Microsoft Defender XDR (Windows Defender) for alert/incident ingestion and disposition sync.
## Overview
The Microsoft Defender XDR integration (**INT-021**) provides **bi-directional** synchronization
between CaseBender and Microsoft's extended detection and response platform, including
**Microsoft Defender for Endpoint (MDE)** and **Microsoft Defender XDR**.
Defender alerts and incidents are ingested into CaseBender, normalized, enriched with
observables and MITRE ATT\&CK techniques, and turned into alerts/cases.
When a CaseBender case is closed, the linked Defender alert/incident is updated with the
matching status, classification, and an audit comment via Microsoft Graph.
This integration uses the **Microsoft Graph Security API** (`https://graph.microsoft.com/v1.0/security`).
It authenticates with an **Azure AD (Entra ID) application** using the OAuth2 client-credentials flow.
## Capabilities
| Capability | Direction | Description |
| ------------------------- | -------------- | -------------------------------------------------------------------------------------------- |
| Alert ingestion | Inbound | Defender alerts are normalized into CaseBender alerts |
| Incident ingestion | Inbound | Defender incidents (with child alerts) are ingested |
| Observable extraction | Inbound | IPs, URLs, file hashes, file names, hostnames, and user accounts are extracted from evidence |
| Asset extraction | Inbound | Device hostname, IP, and OS platform are captured from `devices[]` |
| MITRE ATT\&CK correlation | Inbound | Technique IDs are added as tags and TTPs (e.g. `mitre:T1078`) |
| Alert disposition sync | Outbound | Alert `status`, `classification`, `determination`, and comments are pushed on case close |
| Incident disposition sync | Outbound | Incident `status`, `classification`, `determination`, and comments are pushed on case close |
| Connection test | Bi-directional | Validates OAuth2 credentials and Graph Security API access |
## Prerequisites
A Microsoft Entra ID (Azure AD) tenant with Microsoft Defender XDR or Microsoft Defender
for Endpoint licensed and enabled. You need permission to register applications and grant
admin consent.
The CaseBender deployment must be able to reach:
* `https://login.microsoftonline.com` (OAuth2 token endpoint)
* `https://graph.microsoft.com` (Graph Security API)
You must be able to create and manage integrations in **Settings → Integrations**.
## Part A — Register an Azure AD application
In the [Microsoft Entra admin center](https://entra.microsoft.com), go to
**Identity → Applications → App registrations → New registration**. Give it a name
(e.g. `CaseBender Defender Integration`) and register it.
From the application **Overview**, copy the **Application (client) ID** and the
**Directory (tenant) ID**. You will enter these into CaseBender.
Under **Certificates & secrets → New client secret**, create a secret and copy its
**Value** immediately (it is only shown once).
Under **API permissions → Add a permission → Microsoft Graph → Application permissions**,
add the following and then click **Grant admin consent**:
| Permission | Purpose |
| -------------------------------- | ---------------------------------- |
| `SecurityAlert.ReadWrite.All` | Read and update Defender alerts |
| `SecurityIncident.ReadWrite.All` | Read and update Defender incidents |
Use **Application** permissions (not Delegated). The integration runs headless with the
client-credentials flow and requires tenant admin consent.
## Part B — Configure the integration in CaseBender
Go to **Settings → Integrations → Create**, then choose **Microsoft Defender XDR** from the
**EDR/XDR** category.
Provide the values captured in Part A:
| Field | Description |
| -------------- | ----------------------- |
| `tenantId` | Directory (tenant) ID |
| `clientId` | Application (client) ID |
| `clientSecret` | Client secret value |
Enable the behaviors you need:
| Option | Effect |
| --------------------------- | ----------------------------------------------------------- |
| `syncCaseClose` | Push case closure back to Defender |
| `autoCreateCases` | Automatically create cases from ingested Defender incidents |
| `closeAlertsOnCaseClose` | Resolve the linked Defender **alert** when a case closes |
| `closeIncidentsOnCaseClose` | Resolve the linked Defender **incident** when a case closes |
Use **Test Connection** to validate. CaseBender requests an OAuth2 token and calls
`GET /security/alerts_v2?$top=1`.
A `403` response during the test is treated as **success** — it confirms authentication
worked even when the app has not yet been granted read scope on that specific endpoint.
## Inbound: Ingesting Defender alerts and incidents
### Endpoint
Defender (or an intermediary such as Logic Apps, Sentinel, or a webhook forwarder) sends
alert/incident payloads to the CaseBender ingestion endpoint:
```
POST https:///api/v1/ingest/defender
```
Requests are authenticated with an integration **API key** passed in the `x-api-key` header
(the `authorization: Bearer ` header is also accepted). Defender webhook API keys are
prefixed with `cbr_defender_`.
### Payload formats
Both a **batch** format (Graph `value[]` array) and a **single alert** object are supported.
```bash Batch (Graph value[]) theme={null}
curl -X POST "https:///api/v1/ingest/defender" \
-H "x-api-key: cbr_defender_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"value": [
{
"id": "da637...",
"incidentId": "12345",
"title": "Suspicious PowerShell execution",
"severity": "high",
"status": "new",
"classification": "unknown",
"createdDateTime": "2026-07-03T18:20:00Z",
"mitreTechniques": ["T1059.001"],
"evidence": [
{ "@odata.type": "#microsoft.graph.security.fileEvidence",
"sha256": "9f2b...", "fileName": "payload.ps1" }
]
}
]
}'
```
```bash Single alert theme={null}
curl -X POST "https:///api/v1/ingest/defender" \
-H "x-api-key: cbr_defender_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"id": "da637...",
"title": "Malware detected on endpoint",
"severity": "medium",
"status": "new",
"createdDateTime": "2026-07-03T18:20:00Z"
}'
```
A successful request returns HTTP `202 Accepted`:
```json theme={null}
{ "success": true, "processed": 1, "failed": 0 }
```
### Processing pipeline
The payload flows through CaseBender's ingestion services:
`/api/v1/ingest/defender` validates the source and forwards the request to the ingestion
service (`POST /v1/sources/defender`).
The ingestion service authenticates the API key, validates the payload, and publishes each
alert to the processing queue.
The Defender processor normalizes each record into a CaseBender alert — mapping severity,
building the title/description, extracting observables and device assets, and generating
MITRE TTPs.
### Data mapping reference
**Severity mapping** (Defender → CaseBender 1–4):
| Defender severity | CaseBender severity |
| ----------------- | ------------------- |
| `high` | 1 |
| `medium` | 2 |
| `low` | 3 |
| `informational` | 4 |
| `unknown` | 3 |
**Observable extraction** (from `evidence[]`):
| Evidence field | Observable type |
| --------------- | ------------------------- |
| `ipAddress` | `ip` |
| `url` | `url` |
| `sha256` | `hash` |
| `fileName` | `filename` |
| `deviceDnsName` | `hostname` |
| `userAccount` | `user` (`DOMAIN\account`) |
**Tags** applied on ingest include `defender`, `xdr`, `service:`,
`category:`, `incident` (for incidents), and one `mitre:` tag per MITRE
technique. Ingested records default to **TLP:2** and **PAP:2**.
## Outbound: Syncing case dispositions to Defender
When a case is closed in CaseBender, the `case_closed` event is dispatched to the Defender
handler. If the case is linked to a Defender alert or incident, CaseBender pushes the
resolution back through the Graph Security API.
### How the linked Defender entity is resolved
The handler looks for the Defender identifiers in this order:
1. `extraData.defenderAlertId` / `extraData.defenderIncidentId`
2. `sourceRef` when `extraData.source === "defender"`
3. `sourceRef` when it looks like a Defender alert reference (prefix `da`)
If no alert or incident ID is found, the case close is skipped for this integration.
### Resolution → classification mapping
| CaseBender resolution | Defender classification |
| --------------------- | ------------------------------- |
| `TruePositive` | `truePositive` |
| `FalsePositive` | `falsePositive` |
| `Duplicate` | `informationalExpectedActivity` |
| `NoImpact` | `informationalExpectedActivity` |
| *(other / none)* | `truePositive` (default) |
On close, CaseBender sets the alert/incident `status` to `resolved`, applies the mapped
`classification`, and adds a comment such as:
```
Case closed in CaseBender with resolution:
```
Outbound alert updates require `closeAlertsOnCaseClose` to be enabled; incident updates
require `closeIncidentsOnCaseClose`. If neither is enabled, no outbound sync occurs.
## Security considerations
* **Secret handling** — the client secret is stored in the integration settings; rotate it
on the schedule your organization requires and update the integration when you do.
* **Least privilege** — grant only `SecurityAlert.ReadWrite.All` and
`SecurityIncident.ReadWrite.All`. Do not add broader Graph scopes.
* **Token caching** — access tokens are cached in memory per integration and refreshed one
minute before expiry; no tokens are persisted to disk.
* **Webhook keys** — treat the `cbr_defender_` API key as a secret. Rotate it if exposed and update
the sender configuration.
* **Network** — restrict egress to `login.microsoftonline.com` and `graph.microsoft.com`.
## Troubleshooting
Verify the `tenantId`, `clientId`, and `clientSecret`. Confirm the client secret has not
expired and that admin consent was granted for the Graph application permissions.
The `x-api-key` header is missing or invalid. Confirm you are sending the `cbr_defender_` key that
matches the integration's configured webhook API key.
The payload had neither a `value[]` array nor a top-level `id`. Send a Graph batch object
or a single alert object.
Ensure `closeAlertsOnCaseClose` / `closeIncidentsOnCaseClose` is enabled and that the case
carries a Defender alert/incident ID (via `extraData` or `sourceRef`).
The Azure AD app lacks write permission. Confirm `SecurityAlert.ReadWrite.All` and
`SecurityIncident.ReadWrite.All` are granted with admin consent.
## Related documentation
* [Integrations overview](./introduction.mdx)
* [Microsoft Graph Security API](https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview)
* [Microsoft Defender XDR](https://learn.microsoft.com/en-us/defender-xdr/)
# Introduction
Source: https://docs.casebender.com/en/settings/introduction
Configure and customize your CaseBender environment with comprehensive system settings and preferences.
## Overview
The Settings section provides complete control over your CaseBender environment configuration:
!\[Settings Dashboard]
*Screenshot showing the main settings dashboard*
## Available Settings
### System Configuration
* **Authentication**: Configure authentication methods and security settings
* **Branding**: Customize your instance's look and feel
* **License**: Manage your license and subscription
### Workflow Settings
* **Alert Statuses**: Configure alert status workflows
* **Case Statuses**: Manage case status definitions
* **Templates**: Create and manage templates
* **Workflows**: Define automated workflows
### Data Management
* **Custom Fields**: Define custom fields for various entities
* **Observable Types**: Configure observable type definitions
* **Attack Patterns**: Manage MITRE ATT\&CK® patterns
### Integration Settings
* **AI Configuration**: Set up AI features and preferences
* **Controllers**: Configure external system controllers
* **Integrations**: Manage third-party integrations
## Access Control
Settings access is controlled by:
* User roles
* Permission levels
* Organization settings
* Admin privileges
## Best Practices
### 1. Configuration Management
* Document changes
* Test in staging
* Regular review
* Backup settings
### 2. Access Control
* Limit admin access
* Audit changes
* Define clear roles
* Regular review
### 3. Maintenance
* Regular updates
* Performance monitoring
* Security checks
* Backup verification
## Next Sections
* [Workflow Settings](./workflows/introduction.mdx)
* [Integration Settings](./integrations/introduction.mdx)
# Observable Types
Source: https://docs.casebender.com/en/settings/observable-types/introduction
Configure and manage observable types to categorize and track different types of indicators in your threat intelligence.
## Overview
The Observable Types section allows you to define and manage different types of observables that can be tracked in your threat intelligence operations. These types help categorize various indicators such as IP addresses, domains, file hashes, and other digital artifacts that you monitor.
## Managing Observable Types
### Creating a New Type
Click the "Create" button to add a new observable type:
Configure the following settings:
* Type name
* Description
* Category
* Validation rules
* Display format
## Common Observable Types
### Network Indicators
* IP Address
* IPv4 format
* IPv6 format
* CIDR notation
* Domain Names
* Fully Qualified Domain Names (FQDN)
* Wildcards
* IDN support
* URLs
* Web addresses
* URI patterns
* Protocol specifications
### File Indicators
* File Hashes
* MD5
* SHA-1
* SHA-256
* SHA-512
* File Names
* Extensions
* Patterns
* Regular expressions
* File Paths
* Directory structures
* Path patterns
### System Indicators
* Registry Keys
* Windows registry paths
* Value names
* Data types
* Process Names
* Executable names
* Command lines
* Process patterns
* Service Names
* Windows services
* Unix daemons
* Service patterns
### Communication Indicators
* Email Addresses
* Address formats
* Domain validation
* Pattern matching
* User Accounts
* Usernames
* Account IDs
* Platform identifiers
* Communication Protocols
* Port numbers
* Protocol identifiers
* Service definitions
## Best Practices
### Type Definition
* Use clear, descriptive names
* Provide detailed descriptions
* Set appropriate validation rules
* Include example values
### Organization
* Group related types
* Maintain consistent naming
* Use categories effectively
* Consider type relationships
### Validation Rules
* Define format requirements
* Set value constraints
* Configure pattern matching
* Implement data validation
### Maintenance
* Review type usage
* Update definitions
* Document changes
* Monitor effectiveness
## Using Observable Types
### In Cases
* Threat indicators
* IOC tracking
* Evidence collection
* Pattern matching
### In Analysis
* Indicator correlation
* Pattern detection
* Threat hunting
* Intelligence gathering
### In Reports
* Indicator statistics
* Type distribution
* Trend analysis
* Intelligence reporting
## Related Documentation
* [Case Management](../../cases/introduction.mdx)
# Templates
Source: https://docs.casebender.com/en/settings/templates/introduction
Create and manage templates to standardize case creation and response procedures in your security operations.
## Overview
The Templates section allows you to create and manage predefined templates for various aspects of your security operations. Templates help ensure consistency, save time, and standardize processes across your organization by providing ready-to-use configurations for cases, tasks, and workflows.
## Managing Templates
### Creating a New Template
Click the "Create" button to start creating a new template:
Configure the basic template information:
* Template name
* Description
* Category
* Type (Case/Task/Workflow)
* Access permissions
### Configuring Template Details
Define the comprehensive configuration for your template:
Specify detailed settings:
* Content structure
* Default values
* Required fields
* Automation rules
* Team assignments
### Template Management
View and manage your configured templates:
The template list displays:
* Template name
* Description
* Category
* Type
* Usage count
* Last modified
* Actions
## Template Types
### Case Templates
* Incident Response
* Threat Hunting
* Vulnerability Management
* Security Assessment
* Compliance Review
### Task Templates
* Investigation Steps
* Evidence Collection
* Analysis Procedures
* Remediation Actions
* Status Updates
### Workflow Templates
* Alert Triage
* Incident Response
* Threat Investigation
* Compliance Checks
* Regular Assessments
## Template Components
### Content Structure
* Sections and subsections
* Field definitions
* Dynamic content
* Variable placeholders
### Default Values
* Predefined fields
* Standard responses
* Common settings
* Initial assignments
### Automation Rules
* Automatic field population
* Conditional logic
* Required actions
* Workflow triggers
## Best Practices
### Template Design
* Clear organization
* Consistent structure
* Comprehensive coverage
* User-friendly format
### Content Management
* Regular updates
* Version control
* Change documentation
* Usage tracking
### Team Usage
* Training materials
* Usage guidelines
* Access controls
* Feedback collection
### Quality Assurance
* Regular reviews
* Validation checks
* Effectiveness monitoring
* User feedback
## Using Templates
### In Case Management
* Quick case creation
* Standardized responses
* Consistent documentation
* Efficient handling
### In Task Management
* Structured workflows
* Clear procedures
* Repeatable processes
* Quality assurance
### In Reporting
* Template usage metrics
* Efficiency analysis
* Process improvements
* Success tracking
## Related Documentation
* [Case Management](../../cases/introduction.mdx)
* [Task Management](../../tasks/introduction.mdx)
# Workflows
Source: https://docs.casebender.com/en/settings/workflows/introduction
Create and manage automated workflows to streamline your case management processes in CaseBender.
## Overview
The Workflow Settings section allows you to create automated workflows that execute actions based on specific triggers in your CaseBender instance. This guide will walk you through the process of setting up and configuring workflows.
## Creating a New Workflow
### Step 1: Basic Configuration
Start by clicking the "Create" button and filling out the basic workflow information:
### Step 2: Workflow Details
Configure the detailed settings for your workflow:
Fill out the required information such as:
* Workflow name
* Description
* Priority level
* Execution settings
### Step 3: Organization Settings
Specify which organizations can access and use this workflow:
* Select applicable organizations
* Configure organization-specific settings
* Set access permissions
## Configuring Workflow Logic
### Step 1: Select Trigger
Choose the event that will initiate your workflow:
Available triggers may include:
* Case creation or updates
* Task assignments
* Status changes
* Custom events
### Step 2: Add Actions
Click the plus button on flow edges to add actions to your workflow:
### Step 3: Configure Action
Select and configure each action in your workflow:
### Step 4: Action Details
Provide detailed configuration for each action:
Configure settings such as:
* Action type specific parameters
* Conditional logic
* Input/output mapping
* Error handling
### Step 5: Review Workflow
Review your complete workflow with all configured actions:
## Best Practices
### Workflow Design
* Keep workflows focused and specific
* Use clear, descriptive names
* Document the purpose and expected outcomes
* Test workflows thoroughly before activation
### Performance Considerations
* Optimize action sequences
* Consider execution time and resources
* Monitor workflow performance
* Handle errors appropriately
### Maintenance
* Regularly review and update workflows
* Monitor execution logs
* Keep documentation current
* Validate triggers and actions periodically
# Task Analytics
Source: https://docs.casebender.com/en/tasks/analytics
This guide covers the analytics and reporting features available for monitoring and improving task management efficiency.
## Overview
Task analytics provide insights into:
* Team performance
* Task efficiency
* Resource utilization
* Process bottlenecks
* Quality metrics
!\[Analytics Dashboard]
*Screenshot showing the main analytics dashboard*
## Key Metrics
### 1. Time-Based Metrics
Track time-related performance:
* Average completion time
* Time in each status
* Response time
* Overdue tasks
* Time estimates vs. actuals
### 2. Volume Metrics
Monitor task quantities:
* Total tasks
* Tasks by status
* Tasks by priority
* Tasks by type
* Tasks by assignee
### 3. Quality Metrics
Assess task quality:
* Completion rate
* Rework rate
* Review outcomes
* Error rates
* Customer satisfaction
### 4. Team Metrics
Evaluate team performance:
* Individual workload
* Team capacity
* Assignment balance
* Collaboration level
* Response times
## Dashboard Views
### 1. Executive Dashboard
High-level overview:
* Key performance indicators
* Trend analysis
* Strategic metrics
* Resource allocation
* Risk indicators
!\[Executive Dashboard]
*Screenshot showing executive-level metrics and KPIs*
### 2. Team Dashboard
Team-focused metrics:
* Team performance
* Workload distribution
* Collaboration patterns
* Efficiency metrics
* Quality indicators
!\[Team Dashboard]
*Screenshot showing team-level analytics*
### 3. Personal Dashboard
Individual metrics:
* Task progress
* Time tracking
* Due dates
* Priority queue
* Performance trends
!\[Personal Dashboard]
*Screenshot showing individual performance metrics*
## Reports
### Standard Reports
Pre-configured reports:
1. **Task Summary Report**
* Overall statistics
* Status distribution
* Priority breakdown
* Time analysis
2. **Team Performance Report**
* Individual metrics
* Team comparisons
* Workload analysis
* Efficiency scores
3. **Quality Report**
* Completion rates
* Review outcomes
* Error analysis
* Customer feedback
4. **Time Analysis Report**
* Duration metrics
* Delay analysis
* Response times
* Estimation accuracy
### Custom Reports
Build custom reports with:
* Selected metrics
* Custom filters
* Specific timeframes
* Chosen formats
* Automated delivery
!\[Custom Reports]
*Screenshot showing custom report builder*
## Analytics Features
### 1. Trend Analysis
Track changes over time:
* Historical comparisons
* Pattern recognition
* Seasonal variations
* Growth indicators
* Prediction models
### 2. Bottleneck Detection
Identify process issues:
* Status bottlenecks
* Resource constraints
* Delay patterns
* Process gaps
* Improvement areas
### 3. Resource Analysis
Monitor resource usage:
* Team utilization
* Skill distribution
* Capacity planning
* Workload balance
* Resource gaps
### 4. Performance Forecasting
Predict future trends:
* Completion estimates
* Resource needs
* Capacity requirements
* Risk assessment
* Growth planning
## Visualization Options
### Charts and Graphs
Various visualization types:
* Line charts
* Bar graphs
* Pie charts
* Heat maps
* Scatter plots
* Gantt charts
### Interactive Features
Dynamic analysis tools:
* Drill-down capability
* Custom filters
* Real-time updates
* Export options
* Sharing features
!\[Visualization Tools]
*Screenshot showing various chart types and interactive features*
## Best Practices
### 1. Metric Selection
Choose metrics that:
* Align with goals
* Provide actionable insights
* Are measurable
* Drive improvement
* Support decisions
### 2. Data Quality
Ensure data accuracy:
* Regular validation
* Clean data
* Consistent tracking
* Complete information
* Timely updates
### 3. Report Design
Create effective reports:
* Clear layout
* Relevant metrics
* Visual clarity
* Actionable insights
* Regular updates
### 4. Analysis Process
Follow structured analysis:
* Define objectives
* Gather data
* Analyze patterns
* Draw conclusions
* Make recommendations
## Integration Options
### Data Sources
Connect with:
* Task database
* Time tracking
* Project management
* External systems
* Custom sources
### Export Options
Export data to:
* Excel
* PDF
* CSV
* API endpoints
* Custom formats
## Security and Privacy
### Data Protection
Secure analytics data:
* Access controls
* Data encryption
* Audit logging
* Privacy compliance
* Data retention
### User Permissions
Control access to:
* Metrics visibility
* Report access
* Export rights
* Analysis tools
* Custom reports
For more information about task settings, see [Task Settings](./settings.mdx).
# Creating Tasks
Source: https://docs.casebender.com/en/tasks/creating-tasks
This guide explains the different methods and options available for creating tasks in the system.
## Methods of Creation
### 1. Manual Creation
Tasks can be created manually through several interfaces:
* Using the "New Task" button in the task list
* From within a case detail view
* Through the quick actions menu
* Via the task templates interface
!\[Create Task Dialog]
*Screenshot showing the task creation dialog with all available fields*
### 2. From Templates
Task templates provide standardized formats for common tasks:
* Select from predefined templates
* Use organization-specific templates
* Customize template fields
* Save new templates for reuse
!\[Task Templates]
*Screenshot showing the template selection interface*
### 3. From Cases
Create tasks directly within cases:
* Add investigation tasks
* Create follow-up actions
* Set up review tasks
* Generate documentation tasks
## Required Fields
When creating a task, these fields are mandatory:
* **Title**: Clear description of the task
* **Priority**: Importance level
* **Due Date**: Completion deadline
* **Status**: Initial task state
* **Type**: Task category
## Optional Fields
Additional fields available during task creation:
* **Description**: Detailed task information
* **Assignee**: Responsible team member
* **Parent Case**: Associated case
* **Dependencies**: Related tasks
* **Attachments**: Relevant files
* **Custom Fields**: Organization-specific data
## Task Creation Settings
Administrators can configure task creation options:
* Default values
* Required fields
* Available templates
* Custom fields
* Automation rules
!\[Task Settings]
*Screenshot showing the administrative settings for task creation*
## Task Types
Common task types include:
1. **Investigation Tasks**
* Evidence collection
* Analysis work
* Incident response
2. **Documentation Tasks**
* Report writing
* Evidence documentation
* Procedure updates
3. **Review Tasks**
* Quality assurance
* Peer review
* Management approval
4. **Operational Tasks**
* System updates
* Configuration changes
* Maintenance work
## Priority Levels
Tasks can be assigned different priority levels:
* **Critical**: Immediate attention required
* **High**: Urgent but not critical
* **Medium**: Normal priority
* **Low**: Can be addressed later
## Best Practices
### 1. Task Naming
* Use clear, action-oriented titles
* Include key information in the title
* Follow naming conventions
### 2. Task Planning
* Set realistic deadlines
* Consider dependencies
* Align with team capacity
### 3. Task Assignment
* Match skills to requirements
* Consider workload balance
* Include necessary context
### 4. Task Organization
* Use appropriate templates
* Add relevant tags
* Link related items
## Automation Options
Tasks can be created automatically through:
* Case triggers
* Scheduled events
* Integration webhooks
* Custom workflows
## Task Dependencies
When creating dependent tasks:
1. Identify prerequisites
2. Set logical order
3. Define relationships
4. Configure notifications
## Next Steps
After creating a task:
1. Add detailed description
2. Attach relevant files
3. Set up notifications
4. Brief assigned members
5. Monitor progress
## Integration Features
Tasks integrate with:
* Case management
* Team calendars
* Email notifications
* External systems
For more information on managing tasks, see [Working with Tasks](./working-with-tasks.mdx).
# Task Management
Source: https://docs.casebender.com/en/tasks/introduction
The Task Management system provides a structured way to create, track, and manage action items within cases and investigations.
## Overview
Tasks are actionable items that need to be completed as part of case investigations or general security operations. Each task represents a specific action, assignment, or milestone that contributes to resolving a case or addressing a security concern.
!\[Task List View]
*Screenshot showing the main task list view with filters, priorities, and assignments*
## Key Features
* **Task Lifecycle Management**: Track tasks from creation to completion
* **Priority Levels**: Assign and manage task priorities
* **Due Date Tracking**: Set and monitor task deadlines
* **Team Assignment**: Delegate tasks to team members
* **Progress Tracking**: Monitor task completion status
* **Task Dependencies**: Create and manage task relationships
* **Attachment Support**: Add relevant files and documentation
* **Integration with Cases**: Link tasks to specific cases
## Task Properties
### Core Properties
* **Task ID**: Unique identifier (auto-generated)
* **Title**: Clear description of the task
* **Description**: Detailed information about the task
* **Status**: Current state (Open, In Progress, Completed, etc.)
* **Priority**: Importance level (Low, Medium, High, Critical)
* **Due Date**: Deadline for task completion
* **Type**: Category of task (Investigation, Analysis, Documentation, etc.)
### Metadata
* **Created By**: User who created the task
* **Created At**: Timestamp of task creation
* **Updated At**: Last modification timestamp
* **Assigned To**: Team member responsible for the task
* **Parent Case**: Associated case (if applicable)
* **Completion**: Progress percentage or completion status
## Task Organization
Tasks can be organized in multiple ways:
* **By Case**: Tasks associated with specific cases
* **By Priority**: Grouped by importance level
* **By Status**: Organized by current state
* **By Assignee**: Grouped by team member
* **By Due Date**: Chronological organization
* **Custom Views**: User-defined organization methods
## Related Components
Tasks are integrated with several other components:
* **Cases**: Parent cases that tasks belong to
* **Comments**: Discussion threads on tasks
* **Attachments**: Related files and documents
* **Notifications**: Alerts about task updates
* **Timeline**: Activity history of tasks
* **Reports**: Task status and progress reports
!\[Task Detail View]
*Screenshot showing the detailed view of a task with all its components*
## Task Workflows
Tasks follow defined workflows:
1. **Creation**: Initial task setup
2. **Assignment**: Task delegation
3. **Progress Updates**: Status changes
4. **Review**: Quality checks
5. **Completion**: Task closure
## Best Practices
1. **Clear Descriptions**: Write specific, actionable task descriptions
2. **Realistic Deadlines**: Set achievable due dates
3. **Priority Management**: Assign appropriate priority levels
4. **Regular Updates**: Keep task status current
5. **Documentation**: Maintain clear task notes and attachments
## Next Sections
* [Creating Tasks](./creating-tasks.mdx)
* [Task Workflows](./workflows.mdx)
* [Working with Tasks](./working-with-tasks.mdx)
* [Task Settings](./settings.mdx)
* [Task Analytics](./analytics.mdx)
# Task Settings
Source: https://docs.casebender.com/en/tasks/settings
This guide covers the configuration options and settings available for customizing the task management system.
## Access Settings
Navigate to Settings > Tasks to configure task-related options:
!\[Task Settings Page]
*Screenshot showing the main task settings interface*
## Status Configuration
### Managing Task Statuses
Configure available task statuses:
1. **Create Status**:
* Label and description
* Color coding
* Stage assignment
* Order in workflow
2. **Edit Status**:
* Update properties
* Modify transitions
* Change automation
* Adjust permissions
3. **Delete Status**:
* Remove unused statuses
* Handle existing tasks
* Update workflows
!\[Status Management]
*Screenshot of the status management interface*
## Templates
### Task Templates
Create and manage templates:
* Standard templates
* Team templates
* Project templates
* Custom templates
### Template Properties
Configure template settings:
* Default fields
* Required fields
* Automation rules
* Team assignments
* Dependencies
!\[Template Configuration]
*Screenshot showing template creation and editing*
## Field Configuration
### Custom Fields
Add organization-specific fields:
* Text fields
* Number fields
* Date fields
* Selection fields
* User fields
* Custom types
### Field Properties
Configure field settings:
* Field type
* Default value
* Validation rules
* Required status
* Visibility rules
!\[Custom Fields]
*Screenshot of custom field configuration*
## Automation Settings
### Workflow Rules
Configure automated actions:
1. **Triggers**:
* Status changes
* Priority updates
* Due date changes
* Assignment changes
* Custom events
2. **Actions**:
* Update fields
* Send notifications
* Create tasks
* Update related items
* External integrations
!\[Workflow Automation]
*Screenshot of workflow automation settings*
## Team Settings
### Access Control
Configure team permissions:
* View permissions
* Edit permissions
* Delete permissions
* Assignment rules
* Template access
### Team Organization
Set up team structure:
* Team hierarchy
* User groups
* Role definitions
* Access levels
* Collaboration rules
!\[Team Configuration]
*Screenshot showing team and permission settings*
## Integration Settings
### External Systems
Configure integrations with:
* Project management tools
* Communication platforms
* Calendar systems
* Document storage
* Custom applications
### API Configuration
Manage API settings:
* Authentication
* Rate limits
* Webhooks
* Custom endpoints
* Data mapping
!\[Integration Settings]
*Screenshot of integration configuration*
## Notification Settings
### Email Notifications
Configure email alerts for:
* Task creation
* Status changes
* Comments
* Due dates
* Assignments
* Mentions
### System Notifications
Set up in-app notifications:
* Priority levels
* Delivery methods
* Frequency rules
* Custom triggers
* Team alerts
!\[Notification Configuration]
*Screenshot showing notification settings*
## View Settings
### List View
Configure list display:
* Column selection
* Default sorting
* Grouping options
* Filter presets
* Custom views
### Board View
Configure Kanban boards:
* Column layout
* Card design
* Swimlanes
* WIP limits
* Visual indicators
### Calendar View
Configure calendar display:
* Time scale
* Default view
* Color coding
* Event display
* Resource view
!\[View Configuration]
*Screenshot showing view customization options*
## Analytics Settings
### Metrics
Configure tracking for:
* Completion rates
* Time tracking
* Team performance
* Quality metrics
* Custom KPIs
### Reports
Set up reporting:
* Standard reports
* Custom reports
* Dashboards
* Export options
* Scheduling
!\[Analytics Settings]
*Screenshot of analytics and reporting configuration*
## Best Practices
### 1. Status Configuration
* Use clear names
* Logical workflow
* Consistent colors
* Clear transitions
* Regular review
### 2. Template Management
* Standardize common tasks
* Regular updates
* Team feedback
* Clear documentation
* Version control
### 3. Field Organization
* Logical grouping
* Clear labels
* Helpful hints
* Validation rules
* Regular cleanup
### 4. Automation Rules
* Start simple
* Test thoroughly
* Document rules
* Monitor performance
* Regular review
### 5. Security
* Role-based access
* Regular audits
* Secure integrations
* Data protection
* Compliance checks
For information about working with tasks, see [Working with Tasks](./working-with-tasks.mdx).
# Task Workflows
Source: https://docs.casebender.com/en/tasks/workflows
This guide explains how tasks progress through different stages and how to manage task workflows effectively.
## Task Status Stages
Tasks move through several standard stages:
1. **Open**: Newly created tasks awaiting action
2. **In Progress**: Tasks currently being worked on
3. **Under Review**: Tasks pending verification
4. **Completed**: Successfully finished tasks
5. **Blocked**: Tasks that cannot proceed
6. **Cancelled**: Terminated or obsolete tasks
!\[Task Status Flow]
*Diagram showing the progression of tasks through different status stages*
## Status Management
### Status Properties
Each status has specific properties:
* **Label**: Display name
* **Description**: Status meaning
* **Color**: Visual indicator
* **Stage**: Workflow phase
* **Automation Rules**: Associated actions
### Status Transitions
Valid status changes include:
* Open → In Progress
* In Progress → Under Review
* Under Review → Completed
* Any Status → Blocked
* Any Status → Cancelled
!\[Status Transitions]
*Diagram showing valid status transitions and conditions*
## Task Priorities
### Priority Levels
Tasks can be prioritized as:
1. **Critical**
* Immediate action required
* High business impact
* Time-sensitive issues
2. **High**
* Urgent but not critical
* Significant impact
* Near-term deadlines
3. **Medium**
* Standard priority
* Moderate impact
* Flexible timeline
4. **Low**
* Non-urgent
* Minimal impact
* Background tasks
### Priority Management
Effective priority handling:
* Regular priority reviews
* Escalation procedures
* Impact assessment
* Resource allocation
## Workflow Automation
### Automated Actions
Configure actions for:
* Status changes
* Priority updates
* Assignment changes
* Deadline modifications
* Notification triggers
### Trigger Events
Automation can be triggered by:
* Time-based events
* Status changes
* User actions
* External events
* Related task updates
!\[Workflow Automation]
*Screenshot showing workflow automation configuration*
## Task Dependencies
### Types of Dependencies
1. **Finish to Start**
* Task B can't start until Task A finishes
* Most common dependency type
2. **Start to Start**
* Tasks must start together
* Parallel activities
3. **Finish to Finish**
* Tasks must finish together
* Coordinated completion
4. **Start to Finish**
* Rare, specialized dependency
* Complex relationships
### Managing Dependencies
Best practices include:
* Clear documentation
* Visual representation
* Impact analysis
* Change management
## Progress Tracking
### Completion Metrics
Monitor task progress through:
* Percentage complete
* Milestone achievement
* Time tracking
* Quality metrics
### Progress Updates
Regular updates should include:
* Status changes
* Work completed
* Blockers identified
* Next steps planned
## Team Collaboration
### Assignment Rules
Task assignment considers:
* Team member skills
* Current workload
* Availability
* Domain expertise
### Handoff Procedures
When transferring tasks:
1. Document current status
2. Brief new assignee
3. Transfer resources
4. Update stakeholders
## Reporting and Analytics
### Workflow Metrics
Track key indicators:
* Cycle time
* Lead time
* Resolution time
* Blockers
* Efficiency
### Performance Analysis
Analyze workflow health:
* Bottleneck identification
* Resource utilization
* Quality metrics
* Team performance
!\[Workflow Analytics]
*Screenshot showing workflow analytics dashboard*
## Best Practices
### 1. Status Management
* Use clear status definitions
* Regular status updates
* Proper documentation
* Timely transitions
### 2. Priority Handling
* Regular priority reviews
* Clear escalation paths
* Resource alignment
* Impact assessment
### 3. Workflow Efficiency
* Minimize bottlenecks
* Automate routine tasks
* Clear communication
* Regular reviews
### 4. Team Coordination
* Clear responsibilities
* Effective handoffs
* Regular updates
* Team visibility
## Configuration
### Setting Up Workflows
1. Define status stages
2. Configure transitions
3. Set up automation
4. Test workflows
5. Train team members
### Customization Options
Adapt workflows for:
* Team preferences
* Project requirements
* Organization needs
* Compliance rules
For more information on working with tasks, see [Working with Tasks](./working-with-tasks.mdx).
# Working with Tasks
Source: https://docs.casebender.com/en/tasks/working-with-tasks
This guide covers the day-to-day operations and features available when working with tasks in the system.
## Task Interface
The task interface provides comprehensive task management:
!\[Task Interface]
*Screenshot showing the main task interface with all components*
### Key Areas
1. **Header**: Task title and quick actions
2. **Details Panel**: Core task properties
3. **Activity Feed**: Recent updates
4. **Related Items**: Linked content
## Task Views
### 1. List View
The main task list provides:
* Task overview
* Quick filters
* Bulk actions
* Sort options
* Custom views
!\[Task List]
*Screenshot showing the task list view with various options*
### 2. Board View
Kanban-style task management:
* Status columns
* Drag-and-drop
* Visual indicators
* Quick updates
* Team visibility
!\[Task Board]
*Screenshot showing the Kanban board view*
### 3. Calendar View
Time-based task visualization:
* Due date tracking
* Schedule management
* Timeline view
* Resource planning
* Milestone tracking
!\[Task Calendar]
*Screenshot showing the calendar view*
## Task Actions
### Basic Operations
Common task actions include:
* Edit task details
* Update status
* Change priority
* Modify due date
* Add comments
* Attach files
### Advanced Operations
Additional task capabilities:
* Create subtasks
* Set dependencies
* Clone tasks
* Export data
* Generate reports
## Task Components
### 1. Comments
Facilitate team discussion:
* Add updates
* Ask questions
* Share information
* Mention team members
* Attach files
### 2. Attachments
Manage task-related files:
* Upload documents
* Add screenshots
* Link resources
* Version control
* Preview files
### 3. Subtasks
Break down complex tasks:
* Create checklist items
* Track progress
* Assign ownership
* Set priorities
* Monitor completion
### 4. Time Tracking
Monitor task effort:
* Log work hours
* Track estimates
* Record actuals
* View timesheets
* Analyze efficiency
## Task Organization
### Filtering
Filter tasks by:
* Status
* Priority
* Assignee
* Due date
* Tags
* Custom fields
### Sorting
Arrange tasks by:
* Priority
* Due date
* Creation date
* Status
* Assignee
* Custom order
### Grouping
Group tasks by:
* Status
* Assignee
* Priority
* Project
* Custom fields
* Timeline
## Task Communication
### Notifications
Receive updates about:
* Status changes
* Comments
* Assignments
* Due dates
* Mentions
* Attachments
### Integration
Connect with:
* Email
* Slack
* Teams
* Calendar
* Mobile apps
## Task Analysis
### Progress Tracking
Monitor task progress:
* Completion percentage
* Time tracking
* Milestone status
* Dependency status
* Quality metrics
### Performance Metrics
Analyze task efficiency:
* Cycle time
* Lead time
* Resolution time
* Work distribution
* Team velocity
## Mobile Access
### Mobile Features
Access tasks on mobile:
* View task details
* Update status
* Add comments
* Upload photos
* Receive notifications
!\[Mobile Interface]
*Screenshot showing the mobile task interface*
## Best Practices
### 1. Task Management
* Keep tasks updated
* Use clear titles
* Set realistic deadlines
* Track progress regularly
* Document decisions
### 2. Team Collaboration
* Communicate clearly
* Update promptly
* Share context
* Follow up regularly
* Maintain visibility
### 3. Time Management
* Prioritize effectively
* Track time accurately
* Manage deadlines
* Balance workload
* Plan realistically
### 4. Documentation
* Write clear descriptions
* Attach relevant files
* Record decisions
* Update status
* Maintain history
## Keyboard Shortcuts
Common task shortcuts:
* `Ctrl/Cmd + N`: New task
* `Ctrl/Cmd + E`: Edit task
* `Ctrl/Cmd + D`: Duplicate task
* `Space`: Quick update
* `Esc`: Cancel/Close
## Tips and Tricks
### Productivity Tips
1. Use templates for recurring tasks
2. Set up custom views
3. Use bulk actions
4. Configure notifications
5. Utilize keyboard shortcuts
### Organization Tips
1. Use consistent naming
2. Apply relevant tags
3. Group related tasks
4. Maintain clean lists
5. Archive completed tasks
For information about task workflows and status management, see [Task Workflows](./workflows.mdx).
# Create API Key
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/create
POST /api-keys
Create a new API key
# Delete API Key
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/delete
DELETE /api-keys/{id}
Delete an API key
# Get API Key by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/get-by-id
GET /api-keys/{id}
Retrieve a specific API key
# List API Keys
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/list
GET /api-keys
List all API keys for the current user or organization
# Rotate API Key
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/rotate
POST /api-keys/{id}/rotate
Rotate an API key to generate new credentials
# Get Available Scopes
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/scopes
GET /api-keys/scopes
Get list of available API scopes
# Get API Key Usage Stats
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/stats
GET /api-keys/{id}/stats
Get usage statistics for an API key
# Update API Key
Source: https://docs.casebender.com/en/api-reference/endpoint/api-keys/update
PUT /api-keys/{id}
Update an existing API key
# Get Alert Audit History
Source: https://docs.casebender.com/en/api-reference/endpoint/audit/alert-history
GET /audit/alert/{alertId}
Get the complete audit history for a specific alert
# Get Audit Record
Source: https://docs.casebender.com/en/api-reference/endpoint/audit/get-by-id
GET /audit/{id}
Retrieve a specific audit record
# List Audit Records
Source: https://docs.casebender.com/en/api-reference/endpoint/audit/list
GET /audit
List audit records with optional filters
# Get Audit Statuses
Source: https://docs.casebender.com/en/api-reference/endpoint/audit/statuses
GET /audit/statuses
Get list of available audit statuses
# Bulk Assign Alerts
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-assign
POST /bulk/alerts/assign
Bulk assign alerts to a user (FUNC-014)
# Bulk Delete Alerts
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-delete
DELETE /bulk/alerts
Bulk delete multiple alerts (soft delete) (FUNC-014)
# Bulk Update Alerts
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-update
POST /bulk/alerts
Bulk update multiple alerts (FUNC-014)
# Bulk Assign Cases
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-assign
POST /bulk/cases/assign
Bulk assign cases to a user and/or teams (FUNC-014)
# Bulk Delete Cases
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-delete
DELETE /bulk/cases
Bulk delete multiple cases (soft delete) (FUNC-014)
# Bulk Change Case Status
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-status
POST /bulk/cases/status
Bulk change case status with mandatory task validation (FUNC-014, FUNC-031)
# Bulk Update Case Tags
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-tags
POST /bulk/cases/tags
Bulk add/remove/set tags on cases (FUNC-014)
# Bulk Set Case TLP
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-tlp
POST /bulk/cases/tlp
Bulk set TLP/PAP classification on cases with optional propagation (FUNC-014, FUNC-044)
# Bulk Update Cases
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/cases-update
POST /bulk/cases
Bulk update multiple cases (FUNC-014)
# Delete Comment
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/delete
DELETE /comments/{id}
Delete a comment (soft delete)
# Add Task Comment
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/task-comments-add
POST /tasks/{taskId}/comments
Add a new comment to a task. Supports hierarchical comment structure (FUNC-041).
# Get Task Comments
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/task-comments-get
GET /tasks/{taskId}/comments
Get all comments for a specific task. Supports hierarchical comment structure (FUNC-041).
# Update Comment
Source: https://docs.casebender.com/en/api-reference/endpoint/comments/update
PUT /comments/{id}
Update an existing comment
# Create Custom Field
Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/create
POST /custom-fields
Create a new custom field definition (admin only)
# Delete Custom Field
Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/delete
DELETE /custom-fields/{id}
Delete a custom field definition (admin only)
# Get Custom Field by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/get-by-id
GET /custom-fields/{id}
Retrieve a specific custom field definition
# List Custom Fields
Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/list
GET /custom-fields
List all custom field definitions
# Update Custom Field
Source: https://docs.casebender.com/en/api-reference/endpoint/custom-fields/update
PUT /custom-fields/{id}
Update an existing custom field definition (admin only)
# Create Integration
Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/create
POST /integrations
Create a new integration configuration (admin only)
# Delete Integration
Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/delete
DELETE /integrations/{id}
Delete an integration configuration (admin only)
# Get Integration by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/get-by-id
GET /integrations/{id}
Retrieve a specific integration configuration
# List Integrations
Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/list
GET /integrations
List all configured integrations
# List Integration Types
Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/types
GET /integrations/types
Get all available integration types
# Update Integration
Source: https://docs.casebender.com/en/api-reference/endpoint/integrations/update
PUT /integrations/{id}
Update an existing integration configuration (admin only)
# Get Alerts by Source
Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/alerts-source
GET /metrics/alerts/source
Get alert count grouped by source
# Get Cases by Severity
Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/cases-severity
GET /metrics/cases/severity
Get case count grouped by severity level
# Get Cases by Status
Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/cases-status
GET /metrics/cases/status
Get case count grouped by status
# Get Case Trend
Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/cases-trend
GET /metrics/cases/trend
Get case creation trend over time
# Get Dashboard Metrics
Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/dashboard
GET /metrics/dashboard
Get overview metrics for the dashboard
# Get MTTR
Source: https://docs.casebender.com/en/api-reference/endpoint/metrics/mttr
GET /metrics/mttr
Get Mean Time To Resolve for cases
# Create Organization
Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/create
POST /organizations
Create a new organization (admin only)
# Delete Organization
Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/delete
DELETE /organizations/{id}
Soft delete an organization (admin only)
# Get Organization by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/get-by-id
GET /organizations/{id}
Retrieve a specific organization by its ID
# Get Organization Hierarchy
Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/hierarchy
GET /organizations/hierarchy
Get the organization hierarchy tree
# List Organizations
Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/list
GET /organizations
List all organizations with optional filters
# Update Organization
Source: https://docs.casebender.com/en/api-reference/endpoint/organizations/update
PUT /organizations/{id}
Update an existing organization (admin only)
# Create Playbook
Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/create
POST /playbooks
Create a new playbook
# Delete Playbook
Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/delete
DELETE /playbooks/{id}
Delete a playbook
# Get Playbook Executions
Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/executions
GET /playbooks/{id}/executions
Get execution history for a playbook
# Get Playbook by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/get-by-id
GET /playbooks/{id}
Retrieve a specific playbook by its ID
# List Playbooks
Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/list
GET /playbooks
List all playbooks with optional filters
# Trigger Playbook
Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/trigger
POST /playbooks/{id}/trigger
Manually trigger a playbook execution
# Update Playbook
Source: https://docs.casebender.com/en/api-reference/endpoint/playbooks/update
PUT /playbooks/{id}
Update an existing playbook
# Get SLA Configuration
Source: https://docs.casebender.com/en/api-reference/endpoint/sla/config
GET /sla/config
Get the global SLA configuration
# Get SLA History
Source: https://docs.casebender.com/en/api-reference/endpoint/sla/history
GET /sla/history/{entityType}/{entityId}
Get the SLA status history for a case or alert
# Get SLA Status
Source: https://docs.casebender.com/en/api-reference/endpoint/sla/status
GET /sla/status/{entityType}/{entityId}
Get the current SLA status for a case or alert
# Get SLA Template
Source: https://docs.casebender.com/en/api-reference/endpoint/sla/template-by-id
GET /sla/templates/{id}
Get a specific SLA template by ID
# List SLA Templates
Source: https://docs.casebender.com/en/api-reference/endpoint/sla/templates
GET /sla/templates
Get all SLA templates
# Add User to Team
Source: https://docs.casebender.com/en/api-reference/endpoint/teams/add-user
POST /teams/{id}/users/{userId}
Add a user to a team
# Create Team
Source: https://docs.casebender.com/en/api-reference/endpoint/teams/create
POST /teams
Create a new team (admin only)
# Delete Team
Source: https://docs.casebender.com/en/api-reference/endpoint/teams/delete
DELETE /teams/{id}
Delete a team (admin only)
# Get Team by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/teams/get-by-id
GET /teams/{id}
Retrieve a specific team by its ID
# List Teams
Source: https://docs.casebender.com/en/api-reference/endpoint/teams/list
GET /teams
List all teams with optional filters
# Remove User from Team
Source: https://docs.casebender.com/en/api-reference/endpoint/teams/remove-user
DELETE /teams/{id}/users/{userId}
Remove a user from a team
# Update Team
Source: https://docs.casebender.com/en/api-reference/endpoint/teams/update
PUT /teams/{id}
Update an existing team (admin only)
# Create Template
Source: https://docs.casebender.com/en/api-reference/endpoint/templates/create
POST /templates
Create a new template
# Delete Template
Source: https://docs.casebender.com/en/api-reference/endpoint/templates/delete
DELETE /templates/{id}
Delete a template
# Get Template by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/templates/get-by-id
GET /templates/{id}
Retrieve a specific template
# List Templates
Source: https://docs.casebender.com/en/api-reference/endpoint/templates/list
GET /templates
List all templates with optional entity type filter
# Update Template
Source: https://docs.casebender.com/en/api-reference/endpoint/templates/update
PUT /templates/{id}
Update an existing template
# Get TLP Audit Logs
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/audit-logs
GET /tlp/audit-logs
Get TLP access and change audit logs
# List TLP Change Requests
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/change-requests
GET /tlp/change-requests
List pending TLP change requests awaiting approval
# Check TLP Access
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/check-access
POST /tlp/check-access
Check if the current user has TLP clearance to access an entity
# Get TLP Constants
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/constants
GET /tlp/constants
Get TLP level constants including labels, descriptions, and colors for UI rendering
# Get Entity TLP
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/entity-get
GET /tlp/entity/{type}/{id}
Get the TLP level for a specific entity (case, alert, task, etc.)
# Change Entity TLP
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/entity-update
PUT /tlp/entity/{type}/{id}
Change the TLP level for an entity. May require approval for high TLP levels.
# Process TLP Change Request
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/process-change-request
POST /tlp/change-requests/{id}/process
Approve or reject a pending TLP change request
# Propagate TLP
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/propagate
POST /tlp/propagate
Propagate TLP from a parent entity to its children
# Get User Max TLP
Source: https://docs.casebender.com/en/api-reference/endpoint/tlp/user-max
GET /tlp/user/max
Get the maximum TLP level the current user can access
# Get User by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/users/get-by-id
GET /users/{id}
Retrieve a specific user
# List Users
Source: https://docs.casebender.com/en/api-reference/endpoint/users/list
GET /users
List all users with optional filters
# Get Current User
Source: https://docs.casebender.com/en/api-reference/endpoint/users/me
GET /users/me
Get the currently authenticated user
# Update User
Source: https://docs.casebender.com/en/api-reference/endpoint/users/update
PUT /users/{id}
Update an existing user (admin only)
# Create Webhook
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/create
POST /webhooks
Create a new webhook subscription
# Delete Webhook
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/delete
DELETE /webhooks/{id}
Delete a webhook subscription
# Get Delivery Logs
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/deliveries
GET /webhooks/{id}/deliveries
Get delivery history for a webhook
# List Event Types
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/event-types
GET /webhooks/event-types
Get all available webhook event types
# Get Webhook by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/get-by-id
GET /webhooks/{id}
Retrieve a specific webhook subscription
# List Webhooks
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/list
GET /webhooks
List all webhook subscriptions
# Test Webhook
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/test
POST /webhooks/{id}/test
Send a test payload to a webhook
# Update Webhook
Source: https://docs.casebender.com/en/api-reference/endpoint/webhooks/update
PUT /webhooks/{id}
Update an existing webhook subscription
# Create Workflow
Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/create
POST /workflows
Create a new workflow
# Delete Workflow
Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/delete
DELETE /workflows/{id}
Delete a workflow
# Execute Workflow
Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/execute
POST /workflows/{id}/execute
Execute a workflow manually with provided context
# Get Workflow Executions
Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/executions
GET /workflows/{id}/executions
Get execution history for a workflow
# Get Workflow by ID
Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/get-by-id
GET /workflows/{id}
Retrieve a specific workflow
# List Workflows
Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/list
GET /workflows
List all workflows with optional filters
# Update Workflow
Source: https://docs.casebender.com/en/api-reference/endpoint/workflows/update
PUT /workflows/{id}
Update an existing workflow
# Bulk Merge Alerts
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-merge
POST /bulk/alerts/merge
Bulk merge alerts into a target case (FUNC-014)
# Bulk Change Alert Status
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/alerts-status
POST /bulk/alerts/status
Bulk change alert status (FUNC-014)
# Bulk Delete Observables
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/observables-delete
DELETE /bulk/observables
Bulk delete multiple observables (FUNC-014)
# Bulk Set Observable IOC
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/observables-ioc
POST /bulk/observables/ioc
Bulk set IOC flag on observables (FUNC-014)
# Bulk Update Observables
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/observables-update
POST /bulk/observables
Bulk update multiple observables (FUNC-014)
# Bulk Assign Tasks
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-assign
POST /bulk/tasks/assign
Bulk assign tasks to a user and/or teams (FUNC-014, FUNC-045)
# Bulk Delete Tasks
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-delete
DELETE /bulk/tasks
Bulk delete multiple tasks (soft delete) (FUNC-014)
# Bulk Set Task Mandatory
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-mandatory
POST /bulk/tasks/mandatory
Bulk set mandatory flag on tasks (FUNC-014, FUNC-031)
# Bulk Update Tasks
Source: https://docs.casebender.com/en/api-reference/endpoint/bulk/tasks-update
POST /bulk/tasks
Bulk update multiple tasks (FUNC-014)