DFIRe is case management for digital forensics and incident response. Handle investigations, incidents, evidence with chain of custody, indicator enrichment, compliance deadlines and professional-grade reports, all in one intuitive platform. DFIRe runs in your own infrastructure by default, without vendor access. No seat limitations, no feature tiers.
v1.9.0 · Changelog · 90-day trial · Docker Compose · PostgreSQL 16+ · Linux host
Runs on your servers, behind your firewall. No case data leaves your infrastructure.
One licence covers the whole deployment, whatever the number of users, cases or features you use.
Works in isolated networks with no outbound connectivity required.
DFIRe ships with default playbooks for fifteen common case types. Customize the existing playbooks or create your own from scratch.
Keep your case information organized. Assign actions, keep notes, store indicators of compromise, attach files and write the report on the same platform.
01 / Evidence
All your case evidence in one hierarchy, with configurable attributes and a verifiable custody record. Build and attach runbooks to cover common workflows with confidence. Attach files and notes to all your evidence items, and organize hierarchically.
02 / Response
Track a case from opening to closing through recovery with phase-based actions and action tracking. Set compliance timers to keep track of regulatory deadlines, or track other deadlines like SLAs.
03 / Intelligence
A built-in IOC registry across all STIX 2.1 types, enriched with your own API keys from VirusTotal, AbuseIPDB, AlienVault OTX, Google Safe Browsing, GreyNoise, MalwareBazaar, MISP, Shodan, Spur, ThreatFox, URLhaus and urlscan.io, plus DNS and WHOIS lookups that need no key. Publish and share indicators to supported CTI systems with MISP and TAXII integrations.
Custom case types, severities and assignments. Triage cases escalate into full incident response without losing history.
Deadline tracking for breach notification and other statutory reporting, with your own timer definitions and reminders.
AES-256 with a three-layer key hierarchy for attachments up to 4 GB. Larger images stream to S3, SMB, SFTP or local disk.
Structured sections with a QA workflow, generated evidence inventories, and optional LLM drafting from the provider you choose.
Per-user API keys with full OpenAPI docs, templated outbound webhooks, bidirectional Jira sync, and an MCP server for agents.
OIDC single sign-on, role-based permission groups, and a fail-closed audit log that can forward to your SIEM.
The installer downloads a release-pinned, verified Compose bundle and generates the secrets and configuration for you.
Step 1 / download
curl -fsSL https://dfire.fi/install.sh -o install.shStep 2 / run
chmod +x install.sh && ./install.shThe script walks through configuration and starts the services. Production binds to localhost for your own HTTPS reverse proxy; plain HTTP on 8080 is an explicit evaluation choice. Air-gapped and custom deployments start from the deployment docs.
Price does not move with seat count, company size or which features you switch on.
Free
Granted case by case
9,900 EUR / year
VAT 0%, added per EU rules
Let's talk
Smaller team or tighter budget