Getting started guide

Create and investigate your first incident

Follow one clear path from the first record to an approved report. You do not need previous incident-response software experience.

Practice safely. The screenshots use fictional example data. Start with a training incident and never place real credentials, secrets or unapproved personal data in a test workspace.

Before you start

Complete first launch

Choose the incident data location, create the local administrator and activate your license. Local AI is optional: you can skip it and complete the entire manual evidence-to-report workflow.

  • Use a training incident until your team has agreed its evidence-handling rules.
  • Know where the original evidence is stored and who collected it.
  • Use an account whose role matches the task: Analyst, Reviewer or Approver.

Step 1

Create the incident

  1. Open Incidents and select Create Incident.
  2. Enter a short title that describes what happened, not an assumption about the cause.
  3. Choose the initial severity and status. Add the detected time, organization, environment and analyst when known.
  4. Write a brief factual summary, then select Create Incident.

Good title: “Phishing credential compromise.” Avoid: “User caused the breach.” Conclusions belong in findings after the evidence has been reviewed.

Create Incident form with title, severity, status, detected time, organization, environment, summary and analyst fields
Create the smallest useful record first. Unknown details can be added later.

Step 2

Find and open the incident

Use Search, Status and Severity when the list grows. Select the incident, then choose Open Incident. You can also open a selected row with Enter or by double-clicking it.

IncidentForge incident list with search, status, severity and sort controls and a selected training incident
The list is the starting point for creating, finding and reopening incident workspaces.

Step 3

Confirm the incident context

Read the Overview before adding analysis. Confirm the organization, environment, severity, status, detected time and summary. Use Edit Incident, Change Severity or Change Status when the record needs correction.

Move through the workflow tabs from left to right: Overview, Evidence, Analysis, Report and Audit. The counters show how much structured material the incident currently contains.

Incident workspace Overview showing severity, status, organization, environment and workflow tabs
The Overview keeps the incident’s basic facts visible before deeper investigation begins.

Step 4

Add and preserve evidence

  1. Open Evidence and select Import Evidence for a supported file, or Add Analyst Note for an observation that is not a file.
  2. Record the source, collector and context accurately. Import a controlled copy where your procedure requires the original to remain untouched.
  3. Wait for the parser state. A failed parser does not make the source file disappear; investigate the failure before relying on extracted content.
  4. Open the evidence record and check its metadata and hash before linking it to a timeline event, IOC or finding.
Evidence rule: never rewrite an original file to make it easier to analyze. Create a working copy and document what changed.
Evidence Registry with imported log and email evidence, parser state, source, size and hash columns
The Evidence Registry keeps source files and analyst notes visible as separate, traceable records.

Step 5

Build the investigation record

Analysis is not one large note. Add small, reviewable records and connect each conclusion to the evidence that supports it.

Timeline
Record what happened, when it happened and which evidence supports the event. Distinguish the observed time from the time the event was recorded.
IOCs
Add observable values such as a domain, IP address or file hash. Record confidence and status; an indicator is not automatically proof of compromise.
Findings
State what the evidence supports, explain the reasoning and link the relevant evidence. Keep unchecked assumptions out of approved findings.
MITRE ATT&CK
Map a technique only when the available behavior supports that mapping. The mapping helps communication; it does not replace the evidence.
Recommendations
Describe a concrete response or improvement, then assign an owner, priority and status so the action can be followed.
Analysis Findings view with a high-confidence finding linked to two evidence records
A finding is useful when another person can see the conclusion, confidence, evidence and reasoning together.

Step 6

Use AI drafts safely — or skip them

The AI Assistant can propose draft text from the local incident record when Local AI is configured. Open a proposal in its editor, compare it with the source evidence and save it only after a human review.

  • Treat every AI response as an unverified draft, never as evidence.
  • Reject invented facts, unsupported certainty and recommendations outside the incident context.
  • If Local AI is unavailable, continue manually. It is not required to finish the incident or report.

Step 7

Review, approve and export the report

  1. Open Report, create or update the draft and review every section for accuracy and plain language.
  2. Use the workflow controls to submit the report for review. If sign-in is requested, go to Settings → Local Account, sign in and return to the report.
  3. Resolve readiness blockers. Accept a warning only when the team understands it and records a defensible reason.
  4. The Reviewer challenges the evidence and reasoning. The Approver confirms what becomes final.
  5. After approval, choose Generate / download files and select the required PDF, DOCX, HTML or JSON output.
Approved incident report workspace showing report sections and the Generate or download files action
Export from the approved report state so recipients receive the reviewed version.

Step 8

Close and retain the incident

Change the incident status only when response work and required review are complete. Store the approved export according to your organization’s retention policy. Archiving an IncidentForge record is an organizational action; it does not by itself authorize deletion of original evidence.

Your first incident is ready when:

  • The basic incident context is accurate.
  • Evidence sources and hashes are recorded.
  • Timeline events, IOCs and findings are supported by evidence.
  • Recommendations have clear owners and priorities.
  • A human Reviewer and Approver completed their checks.
  • The approved report was exported and retained correctly.