Skip to content

Case Files

Cases are made up of nodes, which can be items of evidence like files, websites, browser snapshots, entities (such as people, companies, and accounts), or simple text callouts.

Nodes can be joined together by links, which represent relationships.



Two views are available:

Comparison of Graph View and List View
ViewDisplaysNodesLinks
Graph ViewSelected nodes, which can be added or removedNodes are objectsNodes displayed as objects in Graph ViewLinks are linesLinks displayed as lines in Graph View
List ViewAll nodesNodes are rowsNodes displayed as rows in List ViewLinks are indentsLinks displayed as indents in List View

The camera controls allow management of the view. Most camera controls are graph only.


In Graph View, overlay modes can be applied. These overlay modes provide quick visual processing tools to help understand a complex case. These are accessible in the view menu.


The time overlay color codes items in the graph by the recency of the time they were added to the graph. This provides an at-a-glance visual for what areas of the case are currently active.


To hide a node from the graph, select the hide node button in the left panel. This node (and all of its’ associated links) will disappear from the graph view. It will still be visible in list view. Any contents of the node and link are preserved on the case.

To unhide the node, see Adding Nodes to Graph View.


Clicking on a node in list view will open the node in the left panel. It will also expand any linked nodes as nested items underneath the primary node.


At the top of the list view, there are filters for each node type and a search bar. This only filters the nodes in the primary list - all linked nodes will always show.



Add Node to Graph View

To add a node that is not currently in the graph view, select the add node into graph button on the node in list view.


In order to edit a case file, the case must be unlocked. Only one user can edit a case at a time. Users must have edit permissions to unlock the case. If a case is in read only mode, the lock controller will be replaced with a read only icon.

Unlock Case
  • To unlock a case, select the unlock case indicator in the bottom right corner of the case file.


Lock Case
  • To lock the case, select the lock case indicator below the node add options.

When expanded, the notifications tray provides status of file uploads and downloads that are pending. Additionally, any errors that occur will be displayed here, along with a red callout directing your attention to the notifications window.


Nodes are data points within an investigation - evidence, notes, and objects that are tied to the investigation. They are the basic building blocks of cases.

For more information on nodes, see Nodes.


Links represent connections between two nodes. They can have directionality, uncertainty, and a relationship type.

For more information on links, see Links.