Response coordination EU-developed
DFIRTrack
Tracks affected systems, incidents and investigative tasks in larger digital forensics and incident response cases through a shared web interface.
By Mathias Stuhlmacher / DFIRTrack project · Germany
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Response coordination
- Developer or maintainer
- Mathias Stuhlmacher / DFIRTrack project
- Recorded country
- Germany
- Product model
- Open source
- Deployment
- Self-hosted
- Software license
- MIT
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteThe lead contributor and copyright holder Mathias Stuhlmacher publicly lists Germany as his location; this does not establish every contributor's country.
Reported capabilities
- System-based incident tracking
- Shared case and task records
- Ubuntu, Docker and Ansible installation routes
Scope and limits
The upstream README explicitly warns against exposing DFIRTrack on a publicly available server. The German country label is tied to its evidenced lead maintainer.
Inspect the research evidence 4 source observations
identity / capabilities / deployment
README presents a system-based incident tracking application for large cases and documents Ubuntu, Docker and Ansible setup; it warns against public-facing deployment.
Read sourceorigin / country
Lead contributor's self-reported profile identifies Mathias Stuhlmacher and Germany; used only for lead origin.
Read sourcelicense
Actual root license contains MIT License text with Mathias Stuhlmacher copyright.
Read sourcemaintenance
Upstream default-branch Atom feed records a commit on 2026-01-13; branch activity is not a support guarantee.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Move from alert triage to assigned tasks, evidence, shift handoff and closure. A practical case management guide with TheHive and DFIR-IRIS references.
An incident response case management workflow