iris-web
iris-web copied to clipboard
[FR] Add a evidences chain of custody and connect it to assets, tasks, iocs and events
The actual evidences management is too basic for forensic investigations. We need a chain of custody that responds to:
- Who (user)
- What (task)
- How (task)
- When (task)
- On what (assets, evidences)
- What Result (evidences, file)
Moreover, Events, Tasks and IOCs need to be connected to this chain. During investigation, we have to see the source and origin of the event (with link and tree ?).
A very simple chain of custody might look like this:

Optionally, in the far futur, it would be nice to have a screenshot (logical operations) or a photograph (physical operations) attached to a task.