DFIRe (v1.0.1)

Automate DFIRe forensic case management and IOC indicator synchronization from Cortex XSIAM and Cortex XSOAR.

Author
Harri Ruuttila
Support
community
Categories
Forensics & Malware Analysis

Integrations (1)

README

DFIRe

DFIRe is a self-hosted Digital Forensics and Incident Response (DFIR) case management platform built for security professionals. It provides structured investigation workflows, evidence tracking with full chain of custody, IOC indicator management, and NIST-aligned incident response phases — all running on your own infrastructure with AES-256 encryption.

What does this pack do?

This pack integrates Cortex XSIAM with a DFIRe instance to automate your forensics and incident response workflows, including:

Use Cases

Configuration

The integration requires a running DFIRe instance (self-hosted) and an API key generated in System Settings → Integrations within DFIRe. See the integration README for full setup instructions.