An offline incident-response case manager — the container that holds an incident from first alert to lessons-learned. No server, no account, no telemetry, and nothing leaves the machine.
Evidence with a real chain of custody — attach a file and PumaCase hashes it locally with SHA-256, then logs every acquisition, transfer and verification. Verify re-hashes the stored bytes rather than re-reading the recorded hash, which is the difference between an integrity check and a formality
Playbooks that fire on case creation — each incident category carries an editable template task list, created automatically when you open a case of that category. Preparation stops being the phase everyone skips
SLA clocks off the detection time, not the time somebody got around to opening the case — so Detection & Analysis cannot quietly stretch
Bulk IOC import with defang and refang — paste a block of indicators in whatever mangled form they arrived in; typed observables (IP, domain, hash, URL, email, port) come out the other side, each with its own TLP and IOC flag
A contemporaneous timeline — detections, actions, findings and communications in time order, with key events logged for you and every entry editable in place
Your categories, your playbooks, your SLA targets — defined per board from its tab's right-click menu, because no two teams triage the same way
Three views over the same cases — a metrics dashboard, a sortable table, and a drag-between-lanes board
Backup in two parts — a lean .pumapack of boards, cases, observables and custody records, plus a separate .pumaevd holding the raw evidence bytes. Import takes either, in either order
See Method for how these fit together and Keyboard for every shortcut.
Working an incident
PumaCase is built around NIST SP 800-61's four phases. A case's status, tasks and timeline all hang off them, so the model is the app rather than a diagram in a binder.
1 · Do the preparation before the incident — write the playbooks and set the SLA targets on a quiet day, from the board tab's right-click menu. This is the phase that pays for itself and the one that never gets done under pressure.
2 · Open the case at detection, not at convenience — the SLA clocks run from the detection time you enter, so backdating it honestly is what keeps the numbers worth having. Opening the case also fires the category's playbook tasks.
3 · Scope it before you classify it — record observables as you find them and mark each with a TLP level. Decide how far something may travel before you forward it, not after.
4 · Contain, then eradicate, then recover — in that order. A half-cleaned host that is still reachable reinfects the ones you cleaned first. And preserve evidence before you wipe: you cannot re-collect what you destroyed.
5 · Hash evidence when you take it — not later. Log every transfer, and re-verify before you rely on it. If you cannot show the bytes did not change, the artifact will not hold up.
6 · Write the timeline as it happens — memory is the first casualty of an incident. A record built from recollection while writing the report is a story; one written with timestamps as events land is evidence.
7 · Close with the review, and change the playbook — post-incident activity is only worth the meeting if something upstream changes. Edit the category's playbook while the incident is still fresh.
Going deeper
The source is NIST SP 800-61 (Computer Security Incident Handling Guide); the SANS PICERL mnemonic covers the same ground. Rehearse the plan in PumaTTX, and hunt for what detection missed in PumaHunter.
Where your cases live
Every case board is stored in your browser's localStorage, on this device and this browser only. Evidence file bytes are kept locally in this browser's IndexedDB. Nothing is uploaded anywhere.
This is the whole database. If you clear site data, use a private window, switch browsers, or lose the device, your cases and evidence are gone. Back up regularly.
Backing up
The Save button (or ⌘/Ctrl+S) saves all boards and evidence records to a single .pumapack file. For a complete backup also export the evidence bundle separately — use the board's right-click menu → Export board → Evidence bundle. Restore with Import (either file, any order) or by dragging it onto the window.
Clear all local data
Danger zone. This erases every PumaCase board and all evidence in this browser. Export a backup first.
Type DELETE EVERYTHING to confirm:
?
Open this help
⌘/Ctrl + K
Command palette — jump to any view, case board, or action
⌘/Ctrl + S
Export a .pumapack backup
N
New case
1 / 2 / 3
Dashboard / Cases / Board view
/
Focus the search box
Esc
Close case / dialog / menu
About PumaCase
PumaCase is a lightweight, portable, offline IR case management system that runs entirely in your browser. Running an IR CMS in your browser is a terrible idea for a variety of reasons, and you shouldn't do it. That said, sometimes you don't have any better options to keep track, and a nice interface for a JSON beats notepad.exe.
This tool is provided as-is, with no warranties or guarantees. It is not professional advice. By using it you accept full responsibility for any outcomes that result from your use.
About PumaWorx
PumaWorx is a suite of offline, single-HTML productivity apps that run entirely in your local browser. The entire suite is a personal, open source vibecoding project.
This is an offline single-HTML app. No data goes to or from the internet — there is no server, no account, no sync, and no telemetry. Your cases and evidence live in your web browser's localStorage and IndexedDB — on this device, in this browser, and nowhere else.
Your data is YOUR responsibility.
If you clear site data, use a private/incognito window, switch browsers, or lose this device, your cases are gone. Back up regularly with Export in the topbar — it produces a single .pumapack file containing every board, case, and evidence item.