Search...Search plugins and themes...
⌘K
Sign in
  • Get started
  • Download
  • Pricing
  • Enterprise
  • Account
  • Obsidian
  • Overview
  • Sync
  • Publish
  • Canvas
  • Mobile
  • Web Clipper
  • CLI
  • Learn
  • Help
  • Developers
  • Changelog
  • About
  • Roadmap
  • Blog
  • Resources
  • System status
  • License overview
  • Terms of service
  • Privacy policy
  • Security
  • Community
  • Plugins
  • Themes
  • Discord
  • Forum / 中文论坛
  • Merch store
  • Brand guidelines
Follow us
DiscordTwitterBlueskyThreadsMastodonYouTubeGitHub
© 2026 Obsidian

Casefile

Mohammed Farhan AslamMohammed Farhan Aslam495 downloads

Jira-style case and SOC incident tracking in Obsidian: issue keys, epics, kanban swimlanes, SLA timers, IOC handling, reports and shift handover.

Add to Obsidian
  • Overview
  • Scorecard
  • Updates37

Jira-style case & SOC incident tracking, natively in your Obsidian vault. Cases and tasks are plain markdown with YAML frontmatter — portable, searchable, version-controllable, fully offline. No services, no accounts.

Built for a solo SOC analyst's daily shift: triage fast, keep an honest audit trail, hand over cleanly.

What's inside

Case tracking

  • Issue keys (SOC-12) — stable, immutable case addresses, with a global Open case… command (fuzzy search over every key + recently opened cases)
  • Issue types with epic pills; per-project statuses and custom fields
  • Kanban with swimlanes, WIP limits (editable in settings), collapsible columns that still accept drops, and buckets + backlog for planning
  • Table view with sorting, inline editing, and bulk actions — including bulk set-severity / set-verdict for alert storms
  • Query bar with a JQL-lite grammar (sev:>=high sla:breached ioc:evil[.]com), a built-in syntax popover, live match counts, and saved views
  • Right-leaf task detail panel with debounced autosave; Gantt and dashboard views for the bigger picture

SOC pack

  • Severity (the single urgency dial, on any task type) and verdict, with a close-guard so incidents can't be closed without a verdict
  • Per-severity SLA policies with live countdown chips (board, table, detail panel and modal) and breach notices
  • IOC table: bulk paste straight from a report (defanged values are refanged, typed, and deduplicated automatically), rendered defanged everywhere, one-click defanged block export, and an ioc: pivot to find an indicator across cases
  • Optional live reputation checks on indicator rows — VirusTotal (IP, domain, hash, URL; an email is checked by its domain), AbuseIPDB (IP), and the abuse.ch platforms, which share one free auth key from auth.abuse.ch: MalwareBazaar (hashes, via mb-api.abuse.ch), URLhaus (URLs and domains, via urlhaus-api.abuse.ch) and ThreatFox (IPs, via threatfox-api.abuse.ch). Off until you add your own API keys in settings; the indicator value is sent to the provider only when you click the check button, never automatically. This is the plugin's only network use.
  • Incident lifecycle stamps (detected / responded / contained / resolved) with an append-only, per-task activity timeline — nothing edits history
  • Comments, kept structurally separate from factual fields
  • Reports: status/severity breakdowns, SLA compliance, and mean/median time-to-respond / contain / resolve per severity (archived cases included — archiving never erases history)
  • One-command shift handover note, including each open incident's defanged indicators

Data format

One case/task = one markdown file (pm-project / pm-task frontmatter), stored under Cases/ and Tasks/<case>/. If any other plugin that reads the same pm-project/pm-task frontmatter is ever installed in the same vault, keep it disabled while Casefile is enabled: both would write the same files.

Works alongside SOC Toolkit: descriptions are plain notes, so its defang and IP-reputation commands work inside them.

Install

See INSTALL.md — corepack pnpm package builds a portable offline bundle for any vault on any machine.

License

MIT — see LICENSE. Release history in CHANGELOG.md.

HealthExcellent
ReviewSatisfactory
About
Track SOC incidents natively in your Obsidian vault with Jira-style issue keys and portable Markdown YAML frontmatter, fully offline and version-controllable. Manage workflows with Kanban, table and Gantt views, a JQL-lite query bar, per-severity SLAs, IOC handling (defang/refang/dedupe), append-only timelines and handover reports.
Project managementTasksVisualization
Details
Current version
2.20.0
Last updated
5 days ago
Created
2 months ago
Updates
37 releases
Downloads
495
Compatible with
Obsidian 1.7.2+
Platforms
Desktop, Mobile
License
MIT
Report bugRequest featureReport plugin
Author
Mohammed Farhan AslamMohammed Farhan Aslamm0farhan
GitHubm0farhan
  1. Community
  2. Plugins
  3. Project management
  4. Casefile

Related plugins

Tasks

Track tasks across your vault. Supports due dates, recurring tasks, done dates, sub-set of checklist items, and filtering. Maintained by Clare Macrae and Ilyas Landikov, created by Martin Schenck.

TickTickSync

Sync TickTick tasks.

Operon

Task and project management system that unifies inline tasks and file-based tasks in the same workflows with Tables, Filters, Calendars, Kanban boards, Gantt views, Canvas, and time tracking.

dotpm

Full-featured task and project management: stunning Gantt charts, Kanban boards, Table views, customizable fields, due date notifications, dependancies

Base Board

Organize notes into Kanban boards using frontmatter properties. Drag and drop cards between columns powered by Bases.

Apex Dashboard

Your personal command center — memos, todos, and projects in one stunning glassmorphism dashboard.

Kanban

Create Markdown-backed Kanban boards.

TODOseq

Lightweight keyword-based task tracker using Logseq style keywords.

TaskChute Plus

Execute TaskChute that slots today's tasks, tracks projects, adds comments, and keeps you focused on now.

Advanced Canvas

Supercharge your canvas experience. Create presentations, flowcharts and more.