One licence turns all of it on. There are no feature tiers and no per-seat arithmetic, so the only question is whether it fits how your team works. Every capability below links to its documentation if you want the detail before you install.
A case holds the work: actions, notes, files, evidence, indicators and the report. A triage investigation becomes an incident without a handover or a second tool.
Open a case with your own case types, severities and entities. Group related cases into a project when one intrusion turns into several.
Work moves through phases, and each phase carries the actions that belong to it. Assign them, note what happened, and the case shows how far along it is.
Fifteen case types come with a default playbook, so a new case starts with the right steps rather than a blank page. Edit those or write your own. Runbooks hold the how for a single action or evidence item.
One ordered account of what happened and what you did about it. Entries come from the team and from the system, and you can export the timeline into the report.
Track the deadlines you answer for, like GDPR breach notification. Define your own timers, watch the time remaining on the case, and get a reminder while it still matters.
Write the report where the evidence already is. You define the sections, evidence inventories and timelines are generated for you, and a QA step keeps a second reader in the process.
Custody is recorded while the work happens, so nobody has to rebuild the story from tickets and memory a year later when someone asks.
Digital and physical items in one hierarchy, each with a custody record you can print and hand over. Every transfer keeps who, when, where and why, and the chain is hashed so you can show it has not been altered.
Attachments up to 4 GB are encrypted with AES-256 under separate tenant, case and item keys, so a storage backend on its own gives up nothing readable.
Disk images and other large files stream straight to S3-compatible, SMB/CIFS, SFTP or local storage, so file size is never the reason evidence ends up somewhere off the record.
One timestamp format across the case, with timezones handled. Paste a line from a log and the parser reads the time out of it, so entries land in the right order.
DFIRe works with the tools you already run and the intelligence you already pay for. All of it is optional and all of it uses your own keys.
Keep indicators on the case and in a registry that spans cases, so the second sighting of something is obvious. Enrichment runs against VirusTotal, AbuseIPDB, AlienVault OTX, Google Safe Browsing, GreyNoise, MalwareBazaar, MISP, Shodan, Spur, ThreatFox, URLhaus and urlscan.io with your own API keys, and DNS and WHOIS lookups need no key at all.
Publish what you find. A TAXII 2.1 server and a MISP-compatible feed let your threat intel platform, your partners or your sector CERT pull indicators, scoped per consumer.
Coordinate in the channel your team is already in, with case actions available inline. Jira Cloud syncs both ways, and templated webhooks push events to your SIEM, SOAR, XSOAR or XSIAM.
Per-user API keys, service accounts and full OpenAPI docs, so detections can open cases and your own tooling can read what it needs.
Off until you turn it on, and then only through the provider you pick: Anthropic, Gemini, Gemini in your own Google Cloud project, Azure OpenAI, GitHub Models, any OpenAI-compatible endpoint, or a model on your own hardware. It drafts summaries and report sections. The findings stay yours.
Let an agent such as Claude Code work a case like any other responder: the same role limits, the same audit trail, and tool groups you switch on one at a time.
The questions your platform and security teams will ask before this goes anywhere near production.
People sign in through your identity provider over OIDC, including Google Workspace and Microsoft Entra ID. Sessions can be revoked immediately, and you can see where they were used.
Build roles capability by capability and compare two of them side by side before you commit. Access applies per case as well as across the instance.
Every action is written to the audit log before it completes. If that write fails, the action does not happen. Forward entries to your SIEM and keep them under your own retention.
Scheduled AES-256-GCM backups, validated rather than assumed, restored in one step. Backups sit on their own storage target, away from case data.
Docker Compose from a release-pinned bundle, your own PostgreSQL 16+, and a storage backend chosen per role. It runs in isolated networks, and there is no vendor access to your instance.
A software bill of materials and build provenance for both images with every release, plus a written development and disclosure process, for the review your security team is going to run anyway.
A 90-day trial, installed with two commands. Nothing to declare about seat counts, and no case data leaving your network.