Response coordination EU-developed

DFIRTrack

Tracks affected systems, incidents and investigative tasks in larger digital forensics and incident response cases through a shared web interface.

By Mathias Stuhlmacher / DFIRTrack project · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Response coordination
Developer or maintainer
Mathias Stuhlmacher / DFIRTrack project
Recorded country
Germany
Product model
Open source
Deployment
Self-hosted
Software license
MIT
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

The lead contributor and copyright holder Mathias Stuhlmacher publicly lists Germany as his location; this does not establish every contributor's country.

Reported capabilities

  • System-based incident tracking
  • Shared case and task records
  • Ubuntu, Docker and Ansible installation routes

Scope and limits

The upstream README explicitly warns against exposing DFIRTrack on a publicly available server. The German country label is tied to its evidenced lead maintainer.

Inspect the research evidence 4 source observations
  1. identity / capabilities / deployment

    README presents a system-based incident tracking application for large cases and documents Ubuntu, Docker and Ansible setup; it warns against public-facing deployment.

    Read source
  2. origin / country

    Lead contributor's self-reported profile identifies Mathias Stuhlmacher and Germany; used only for lead origin.

    Read source
  3. license

    Actual root license contains MIT License text with Mathias Stuhlmacher copyright.

    Read source
  4. maintenance

    Upstream default-branch Atom feed records a commit on 2026-01-13; branch activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Move from alert triage to assigned tasks, evidence, shift handoff and closure. A practical case management guide with TheHive and DFIR-IRIS references.

An incident response case management workflow