-
-
Notifications
You must be signed in to change notification settings - Fork 1
Case Notes
The Notes tab is where an investigation's narrative lives: analyst notes in folders, written
in Markdown, saved as you type, versioned, shared, and — since IRIS-NG-v2.3.0 — tagged and
wired to the case's indicators. This page describes the tab as shipped in IRIS-NG; the
version notes say what arrived when.
The left pane is the directory tree: folders (nestable), each with its note count, and the notes inside them. Right-click a folder to add a note or a sub-folder, rename, move or delete it; right-click a note to copy its link or its Markdown link, move it, or delete it. Deleting a folder deletes every note and sub-folder inside it — there is no move-to-root (that behaviour belongs to war-room notes, a separate feature). The search box above the tree filters the tree to matching notes and shows their ancestor folders.
The right pane is the open note: its title (click to rename), its id and UUID, the tags row, the toolbar, the Markdown editor on the left and the rendered preview on the right. The preview follows the editor; the expand toggle hides the editor to read the note full width.
The editor is a Markdown editor with a toolbar and shortcuts: CTRL-S save, CTRL-B bold,
CTRL-I italic, CTRL-SHIFT-1 to 4 headings, CTRL-` code, CTRL-K link, plus table,
bullet and numbered list snippets. Pasting an image uploads it to the case datastore in the
background and inserts the Markdown image link.
Autosave fires about ten seconds after the last keystroke; the cloud icon beside the title means it is on, and the save button turns red while a change is unsaved. Every save that changes the title or the text records a revision: the clock icon lists them with author and time, previews any of them, reverts to one, or deletes one.
Several people can have the same note open. Their avatars appear beside the toolbar, edits are relayed live between them, and "last saved by" tells you whose save landed last.
Each note also carries comments (the speech-bubble button), custom attributes (the
case's note attribute set), a shareable link (/case/notes?cid=<case>&shared=<note_id> opens
that note), a Copy MD link that pastes as a Markdown link with a tag glyph, and a download
of the raw Markdown.
Since IRIS-NG-v2.3.0. The Tags row under the title takes tags the way every other case
object does — comma-separated, with autocomplete from the tags already known to the
instance and the bundled MISP taxonomy and galaxy catalog. A tag saves with the note, and
adding or removing one in the widget saves immediately.
- Each note's tags show as chips in the tree; clicking a chip filters the tree to the notes carrying that tag, and clear restores it. The search box matches tags too.
- The ✨ Suggest tags pill asks the AI tag suggester with the note's title, folder and text. For notes the suggester may propose, besides MISP catalog tags, any tag already in use elsewhere in the case (the case itself, its notes, IOCs, assets, tasks and timeline events) — narrative notes are usually labelled by case convention rather than by taxonomy, and this keeps a case's labels consistent without letting the model invent new ones. Nothing is written until you accept a chip.
- Tags travel with the note into the AI summary and chat payloads, the
.docxreport (note.note_tagson each note) and the case export.
Two AI-assisted actions on the toolbar, and one that needs no model.
✨ Extract IOCs reads the note text and proposes indicators with their type, a confidence, a reason and a noise flag (a public DNS resolver, a CDN domain). Each row has + add, which creates the indicator in the case and records this note as its source; Accept all adds every row, one after another. A row whose indicator the case already holds shows link instead. See IOC extraction.
Mentions become links (since IRIS-NG-v2.3.0). When an indicator is added or linked
from that panel, every mention of it in the note text is rewritten as a link to the
indicator on the IOC tab — the Copy MD link shape with the value as the link text — and
the note is saved. Defanged spellings (hxxp, [.], (.), [dot], [at], [:]) are
recognised and kept as the link text, so the note stays safe to paste anywhere. A mention
already inside a link, a code span, a fenced block or an HTML tag is left alone; a value
inside a longer hostname or hash is not a mention; a URL wins over the domain inside it;
running it twice changes nothing.
🔗 Link known IOCs does the same for every indicator already on the case, without calling a model — for notes written after the indicators existed, or pasted in from elsewhere. The status beside the button says how many mentions of how many indicators were linked, or that nothing unlinked was found (see Troubleshooting for what does and does not count as a mention).
Every link records the note as a source of the indicator, so the indicator's Notes tab on the IOC page lists the notes that mention it, and the knowledge map draws the note-to-indicator edge. Clicking a link opens the IOC tab with that indicator selected and its side panel open.
The chat bar at the bottom of the tab is the case chat in its notes variant: it sees the whole case, with the notes (titles, tags and text) in front, and offers starters such as Summarise all the notes, Which note has the weakest evidence backing?, What gaps would a peer reviewer flag? and Are any notes contradicting the timeline?. Answers end with follow-up chips.
- War rooms show the notes of every attached case read-only in the room's Notes tab, beside the room's own notes (War Rooms).
-
Reports receive every note with its folder, text and tags; the bundled and custom
.docxtemplates decide what to render (Architecture). - Export / import carries notes with their folder path, tags and custom attributes (Case Export / Import).
-
API: the legacy
/case/notes/*routes (add, update, detail, search, directory tree) are the ones the page uses;note_tagsrides on them sinceIRIS-NG-v2.3.0(API Reference).