Incident response, start to finish, in one workspace. 

DFIR-IRIS is the open-source platform where responders run investigations together — cases, timelines, evidence and war rooms in one workspace, on your own infrastructure.

Feeds, enriches and exports across your stack

MISPVirusTotalIntelOwlSIEMEDRWebhooksREST APIIrisCheck
v3Coming soon

IRIS v3 is coming in to land. 

Everything on this page is v3 — the rebuilt case view, war rooms with teams and threads, the new API. It is in final testing now. Follow the approach and we'll tell you the moment it touches down.

One case. The whole investigation. 

Open a case in seconds. Assets, IOCs, tasks and evidence, captured as the investigation moves and kept honest by a full audit trail.

IRISv3.0.0
Case · #1042

Ransomware — HQ file server

  • Severity-aware case header with status pills
  • Assets, IOCs, tasks, evidence linked together
  • Full audit trail per case
  • Rich text notes, saved as you type

Where the team meets. And decisions get made. 

Real-time chat, threads, teams and slash commands. Every decision on the record, every attachment routed straight into evidence.

IRISv3.0.0
War Room · WR#1

Ransomware · 0600

  • Per-war-room teams and topics
  • Threaded chat with slash commands
  • Attachments routed straight into evidence
  • Every decision on the record

The full DFIR toolkit. One open-source platform. 

Alerts

SIEM, EDR, and REST-fed alerts land in one queue — cluster, triage, and promote to a case in one click.

Assets

Hosts, users, endpoints, accounts — every asset touched by the incident tracked in the case record.

IOCs

Indicators typed, tagged, and shareable. Enrich them from VirusTotal or MISP without leaving the case.

Tasks

Assign work, track state, and keep the checklist honest. Tasks live inside cases and inside war rooms.

Notes

Rich-text notes saved as you type. Group them by directory, link them to assets, keep the narrative alive.

Evidence

Drop artefacts, IRIS hashes and tags them. Chain of custody, verified by SHA-256, ready to hand off.

Reports

One click turns the case into an exec summary, technical report, or court-ready PDF. Templates configurable.

Timeline

Every event, alert, and action on one investigation timeline — enriched with evidence, exportable as a narrative.

War Rooms

Real-time chat, slash commands, per-room teams. Every decision on the record, every attachment routed to evidence.

Access Control

Case-level and group-level RBAC. Restrict who can read, edit, or export — with a full audit trail behind every action.

Modules

First-party and community modules — IrisMISP, IrisVT, IrisCheck, IrisWebHooks. 162 hook bindings, all auditable.

REST API

Every action in IRIS is scriptable. Push, pull, and automate — IRIS is a platform, not a silo.

IRIS is free. Its backers keep it flying. 

As a free and open-source project, we rely on our community to keep development going and the platform improving. If IRIS is useful to your team, please consider supporting us financially through OpenCollective.

Deutsche Telekom Security GmbH
MT
Anonymous
maof97
Anonymous
SocFortress
Corporationwww.socfortress.co
SecurityDungeon
Corporation
RTeam SOC
Corporation
Jones
Anonymous
Shanief W.
Anonymous
ESET Team
Corporation — during Locked Shields 2024

Run your next case in IRIS. Deploy it on your own metal. 

Stand IRIS up in minutes with Docker, or try the hosted demo first. No licence to negotiate, no data leaving your network.