Principalele funcționalități ale dfir-iris/iris-web sunt: Incident Response Management, Forensics and Incident Response, Security Lab Environments, Incident Response Platforms.
Alternativele open-source pentru dfir-iris/iris-web includ: thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… netflix/dispatch — Dispatch is an incident response orchestration platform that automates the coordination of detection, participant… matanolabs/matano — Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale… google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… dfirkuiper/kuiper — Digital Forensics Investigation Platform.
TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid