Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

DFIR-IRIS

Collaborative incident response platform: cases, timelines, evidence, tasks, and integrations with MISP, VT, and webhooks.

Why it is included

Major open alternative to ticket-only IR when teams need a dedicated case workspace with automation hooks.

Best for

CSIRTs coordinating multi-analyst response with structured timelines and IOC management.

Strengths

  • Case model
  • API-first
  • MISP/IntelOwl-class integrations

Limitations

  • Operational effort to harden and backup; compare to TheHive/Cortex habits

Good alternatives

TheHive · RTIR · commercial SOAR

Related tools