Response coordination CSIRT-led

DFIR-IRIS

Collaborative incident response workspace for sharing technical investigation details, organizing cases, and tracking evidence and timelines across responders.

By DFIR-IRIS community · France

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Response coordination
Developer or maintainer
DFIR-IRIS community
Recorded country
France
Product model
Open source
Deployment
Self-hosted
Software license
LGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

Originated inside the Airbus Cybersecurity commercial CSIRT in France in 2019; now maintained by the independent DFIR-IRIS project.

Reported capabilities

  • Multi-user web workspace shares investigation details and cases.
  • Stable v2.4.29 remains recommended for production while v3 is beta.
  • The umbrella project is licensed LGPL-3.0.

Scope and limits

The current v3 branch is beta and the README advises using stable v2.4.29 for production; the preview deployment is only a demonstration.

Inspect the research evidence 4 source observations
  1. origin / country

    The project team recounts that the idea and first implementation arose within the Airbus Cybersecurity commercial CSIRT in France in 2019, with open release supported by Airbus in 2021.

    Read source
  2. identity / capabilities / deployment

    Current umbrella README describes a collaborative investigation web platform, its Docker Compose deployment, and the three coordinated v3 repositories.

    Read source
  3. license

    Upstream license text is GNU Lesser General Public License version 3.

    Read source
  4. maintenance

    The latest stable release page lists v2.4.29 with security and UI fixes; the README separately identifies the v3 branch as beta.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

MISP Integration

The bundled IrisMISP module enriches supported IOC types using one configured MISP instance. It needs configuration before use; automatic lookups on IOC creation or update are opt-in.

Put the tool in context.

Move from alert triage to assigned tasks, evidence, shift handoff and closure. A practical case management guide with TheHive and DFIR-IRIS references.

An incident response case management workflow