{"repo":"dfir-iris/iris-web","free":true,"listed":false,"github":"https://github.com/dfir-iris/iris-web","clone":"git clone https://github.com/dfir-iris/iris-web.git","description":"Collaborative Incident Response platform","language":"Python","stars":1537,"topics":["forensic","incident-response","csirt-tooling","python","digital-forensics","digital-forensics-incident-response","forensic-analysis","forensic-tools"],"license":"LGPL-3.0","category":"databases-storage","readme_excerpt":"Incident Response Investigation System Current Version v2.4.20 Online Demonstration IRIS Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Table of contents - Getting Started - Run IrisWeb - Configuration - Versioning - Showcase - Documentation - Upgrades - API - Help - Considerations - License Getting started It is divided in two main parts, IrisWeb and IrisModules. - IrisWeb is the web application which contains the core of Iris (web interface, database management, etc). - IrisModules are extensions of the core that allow third parties to process data via Iris (eg enrich IOCs with MISP and VT, upload and injection of EVTX into Splunk). IrisWeb can work without any modules though defaults ones are preinstalled. Head to Manage Modules in the UI to configure and enable them. Running Iris To ease the installation and upgrades, Iris is shipped in Docker containers. Thanks to Docker compose, it can be ready in a few minutes. Iris shall be available on the host interface, port 443, protocol HTTPS - https:// . By default, an administrator account is created. The password is printed in stdout the very first time Iris is started. It won't be printed anymore after that. WARNING :: post init :: create safe admin :: can be searched in the logs of the webapp docker to find the password. The initial password can be set via the configuration. Iris is split on 5 Docker services, each with a different role. - app : The co","default_branch":null,"files":null,"tree":[],"storefront":"/r/dfir-iris","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dfir-iris/iris-web/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}