Comprehensive case management for DFIR professionals. Track investigations, manage evidence, coordinate incident response, and generate reports — all in one secure, self-hosted platform.
30-day free trial. No credit card required.
DFIRe is a fully self-hosted solution. Deploy it on your own servers, behind your firewall, with your security policies. No incident data ever leaves your infrastructure.
Everything your team needs to manage forensic investigations and incident response workflows.
Organize investigations with customizable case types, severity levels, and team assignments. Support for both traditional investigations and incident response workflows.
Track digital and physical evidence with detailed metadata, chain of custody, legal ownership, and hierarchical organization. Customize your evidence types with configurable attributes.
Visual timeline for tracking incident phases, from detection through recovery. Guided response actions with phase-based checklists and automatic progress tracking.
Built-in SLA tracking for regulatory requirements like GDPR breach notifications. Automatic reminders and deadline tracking to ensure compliance.
AES-256 encryption for all file and image attachments with a three-layer key hierarchy. Per-case and per-item encryption keys ensure data isolation and secure deletion. Your data is unreadable even if the storage backend gets compromised.
Atomic role-based access control with customizable permission groups. Define granular rights for your team with lead investigators, case members, and viewers. Slack integration for collaboration, workflow management and notifications.
Structured investigation reports with customizable sections, QA workflow, and markdown support. Auto-generated evidence inventories and timelines.
Outgoing webhooks for SIEM integration and notifications. Incoming webhooks allow SOAR platforms to create cases automatically.
SSO integration via the OIDC standard, compatible with any OIDC provider including Google Workspace, Microsoft Entra ID, and Auth0. Session management with instant revocation and IP tracking.
Modern, intuitive interface designed for efficiency.
Dashboard
Incident Timeline
Response Actions
Evidence Management
Compliance Timers
Report Editor
Case Configuration
Webhook Integrations
All features included. No per-user fees. No feature tiers.
Need more time? Contact contact@dfire.fi for an extended trial.
Deploy DFIRe with Docker Compose. Self-hosted means your data stays on your infrastructure.
curl -fsSL https://dfire.fi/install.sh -o install.sh
chmod +x install.sh && ./install.sh
The script will guide you through configuration and start the services.
https://your-server:443
Create your admin account and start investigating.
For advanced deployments, custom configurations, or air-gapped environments, see the deployment documentation.