Skip to main content
Cyberstage :: Case and Evidence Management > Case Summary
Contact Page | Privacy Policy

Case Workflow

  1. Upload Evidence
  2. Add evidence containers or individual artifact files to the case. Supported Windows artifacts include EVTX event logs, Registry hives, MFT data, runtime process data, and runtime network connection data.

  3. Review Processing Status
  4. Track planning, discovery, processing, maintenance, and finishing tasks. Resolve failed tasks, approve pending work when auto discovery is disabled, or ignore evidence that should not be processed.

  5. Review Threat Detections
  6. Use the Threat Detections page to review Sigma matches, filter by evidence source, and drill into detections by rule, technique, or source system.

  7. Review Windows Artifacts:

    Inspect parsed artifact data directly when you need file-level, host-level, or source-specific context beyond detections.

  8. Review the Timeline
  9. Use the timeline to correlate events, detections, file activity, and artifact records in chronological order.

  10. Export Data
  11. Export processed detections and case data for reporting, handoff, or follow-up analysis.