See a real deliverable

Request a sample MSP incident evidence pack

See what CasePack can produce for a security incident: client-ready report, evidence index, timeline, NIS2-style milestone view, audit history, and ZIP/PDF export structure.

The sample pack is fictional and safe to review. It contains no real client data, credentials, malware, or personal information.

What is inside the sample pack?

The sample evidence pack includes:

  • executive/client summary PDF
  • incident details
  • timeline of detection, containment, eradication, recovery, and closure
  • evidence index
  • sample screenshots
  • sample log excerpts
  • sample IOCs
  • remediation summary
  • recommendations
  • NIS2-style milestone status
  • audit activity summary
  • ZIP folder/manifest structure

Sample scenario

Client: Contoso Manufacturing. Incident: Suspicious Microsoft 365 login and ransomware containment exercise. Severity: High.

Purpose: Demonstrate how an MSP can package incident details, evidence, timeline, remediation, and closure notes into a professional deliverable.

A client reports suspicious login activity for a finance user. The MSP investigates sign-in logs, reviews MFA status, checks endpoint alerts, resets credentials, revokes sessions, verifies no mailbox forwarding rules were created, reviews backup posture, and prepares a client-facing incident summary.

CasePack is used to capture:

  • incident summary and severity
  • affected user count
  • screenshots and log excerpts
  • response timeline
  • containment and recovery actions
  • client communication notes
  • root cause and lessons learned
  • final evidence pack export

How to evaluate the sample

When reviewing the sample, ask:

  1. 1

    Would this be clearer than a raw PSA ticket export?

  2. 2

    Could your technicians follow this structure consistently?

  3. 3

    Would your client understand what happened and what was done?

  4. 4

    Would this help during audit, cyber insurance, or internal review?

  5. 5

    Which parts would you want co-branded or customized?

What you will see

A concise client-ready explanation of what happened, what was affected, and what actions were taken — rendered from the actual evidence-pack PDF.
A chronological record of detection, containment, eradication, recovery, notes, and closure events.
A structured list of screenshots, logs, PDFs, IOCs, and supporting artifacts.
The ZIP package structure and signed manifest designed for handover, review, and audit preparation.

Request the sample evidence pack

Enter your work email and we will send the fictional sample pack so you can review the report structure, evidence index, timeline, and export format.

The sample pack is fictional and safe to review. No spam.

Want this output for your own MSP workflow?

CasePack helps MSPs turn incident tickets, evidence, timelines, and notes into professional evidence packages for clients, auditors, insurers, and internal review.

Frequently asked questions

No. The sample is fictional and safe to review, with no real client data, credentials, malware, or personal information.

The sample is a package containing a sample PDF report, evidence index, timeline preview, sample artifacts, and manifest-style structure.

Yes. CasePack is designed to help MSPs create incident records, upload evidence, build timelines, generate reports, and export evidence packs.

Co-branding is available as a partner/enterprise or roadmap/customization option.

CasePack can help organize NIS2-style milestones and incident notification reports, but legal/compliance review remains your responsibility.

See what a professional incident evidence pack looks like

Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.