See what a professional incident evidence pack looks like
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
CasePack helps MSPs using HaloPSA-style ticket workflows create structured incident records, collect evidence, build timelines, generate reports, and export professional PDF/ZIP evidence packs.
Your PSA is still the right place for service tickets, operational workflow, assignment, SLA context, and day-to-day work management. CasePack adds the incident evidence and reporting layer that MSPs need after or during the response:
Incident ticket starts in HaloPSA
A ticket is created from a client report, alert, triage workflow, or security process.
Create a CasePack incident through webhook intake
CasePack supports webhook intake for HaloPSA-style payloads. For HaloPSA payloads, CasePack maps common fields like summary to incident title, details to incident description, and priority_name to severity where available.
Add the evidence that does not belong buried in ticket comments
Upload screenshots, logs, IOCs, PDFs, exports, emails, endpoint data, or other supporting files.
Build a chronology of the response
Use the timeline to capture containment, eradication, recovery, client communication, and analyst notes.
Generate a report and evidence pack
Produce an executive/client summary, final evidence pack, or NIS2-style notification report where relevant.
Instead of sending a raw ticket thread, your MSP can provide:
Security incidents are high-trust moments. A professional close-out package helps your team show the work, reduce confusion, and demonstrate a repeatable process.
CasePack makes the report and evidence workflow easier to standardize across technicians and clients.
In CasePack, open the target tenant workspace
Navigate to Webhooks
Create a new webhook and select HaloPSA as provider
Copy the generated webhook URL
Configure the HaloPSA-side automation or integration to send incident data to CasePack
Test with a low-severity sample incident
Security note: Treat the webhook URL as a secret and rotate it if exposed.
CasePack helps your MSP turn incident tickets into structured records with evidence, timelines, reports, audit logs, and exports.
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
HaloPSA is a trademark of its respective owner. CasePack is not affiliated with or endorsed by HaloPSA.