Open Source Incident Response Platform - Your SOC Needs This!

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 ก.พ. 2025
  • Join me as we replace TheHIVE with DFIR-IRIS. The new open source Incident Response Platform!
    Forgot to add a challenge flag in the video, so this week is an easy one :)
    Flag: gvASDY63!
    Blog: / your-open-source-incid...
    Check Them Out: dfir-iris.org/
    DFIR-IRIS Discord: / discord
    🚩 CTF Challenge: ctf.socfortres...
    📩 Contact Me: taylor.walton@socfortress.co
    ℹ️ LinkedIn: / socfortressmdr
    🧾 Our Blog: / socfortress
    ☕ Buy Me A Coffee: bit.ly/3woh21M
    🚀 Security Operations Center as a Service: www.socfortres...
    ✅ Free For Life Tier: www.socfortres...
    👨🏻‍💻 Professional Services: www.socfortres...
    👾 Discord Channel: / discord
    Series Playlist: • World's Best SIEM Stack

ความคิดเห็น • 38

  • @rockdarko440
    @rockdarko440 2 ปีที่แล้ว +7

    What I really enjoy about your content is that you don't only show solutions but really go in-depth in them and demonstrate how they apply in the real world. What would be really awesome is a video on the different solutions you go over on your channel and explain different ways they complement each other. Thanks again man!

  • @deepaknarayanan3619
    @deepaknarayanan3619 2 ปีที่แล้ว +1

    Your videos are unique and extremely useful. Great Contents , please do continue with more SOC related contents. I'm a senior cybersecurity engineer and your videos helps my team alot. All the best brother..

  • @user-um3sy6qj4c
    @user-um3sy6qj4c 2 ปีที่แล้ว +3

    Hopefully you will demonstrate how to create a customized Incident Report Template by using DFIR-IRIS. Thanks

  • @mit0w
    @mit0w 10 วันที่ผ่านมา

    Love your videos btw

  • @mauriciob3334
    @mauriciob3334 2 ปีที่แล้ว +2

    I think knowing that cortex is still open source it would be nice to create a connection between iris and cortex

  • @user-um3sy6qj4c
    @user-um3sy6qj4c 2 ปีที่แล้ว +1

    Thank you, very helpful information

  • @FreeSOC-de
    @FreeSOC-de 2 ปีที่แล้ว +6

    Hi Taylor, looks very interesting - is it possible to archive closed cases to MISP and is it directly usable to analyse with cortex, or did i have to use shuffle for interact between Wazuh, Cortex, MISP and DFIR-ISIS?

  • @cesars.3210
    @cesars.3210 8 หลายเดือนก่อน +1

    Hello, did you do a video about shuffle automation with IRIS ?

  • @ithiou92
    @ithiou92 2 ปีที่แล้ว +1

    Great
    This tool is very useful 👍👍
    Can we integrate with ELK?

  • @alimachiavelli8917
    @alimachiavelli8917 2 ปีที่แล้ว

    Good one @Taylor

  • @logicbypass
    @logicbypass 2 ปีที่แล้ว +1

    Hi, thx for the video, as always enjoy your content!
    Did you know of any self-hosted solutions that are as complex as Microsoft 365 Defender stack?
    (Sentinel,MDE,MDI,MDO,MDC,MDCA,AAD,DLP,TIP,MDAV..).
    Closer to the "Zero Trust" concept than "Network-Based Security".
    Thx.

  • @lucasvalentelima7331
    @lucasvalentelima7331 2 ปีที่แล้ว +3

    Your terminal looks amazing! 😮 What software is it?

    • @MADhatter_AIM
      @MADhatter_AIM 2 ปีที่แล้ว +1

      i want to know this also, i saw auto-complete etc ...

    • @brokstine
      @brokstine ปีที่แล้ว

      Termius

    • @da2ricky
      @da2ricky ปีที่แล้ว

      I was digging through comments to find this out myself

  • @llfrater19
    @llfrater19 หลายเดือนก่อน

    Sorry, the page you are looking for is currently unavailable.
    Please try again later.
    If you are the system administrator of this resource then you should check the error log for details.
    Faithfully yours, nginx.

  • @ICanEatThat
    @ICanEatThat 2 ปีที่แล้ว +2

    Does IRIS support multi tenants like TheHive, would be so cool if it does

  • @IvanCenturionGiles
    @IvanCenturionGiles 2 ปีที่แล้ว

    The tool looks very useful

  • @markverstappen1365
    @markverstappen1365 ปีที่แล้ว

    Great video!!!
    Could you also make a (step-by-step) video how to get it working when someone is using Portainer as containermanagement software.
    Can't get it to work due to the use of all the interconnected Dockerfiles and scripts. All the images need to be constructed and then in one docker-compose file without all the seperate buildsteps you can start them in Portainer under stacks. But could not get it to work 😞

  • @bdcirt6125
    @bdcirt6125 ปีที่แล้ว

    Nice tutorial :) How to post the elastalerts from praeco to iris?

  • @vector1one
    @vector1one 2 ปีที่แล้ว

    This is cool, I was looking for a thehive replacement. Is there a tie in for intelowl much like the hive has cortex?

  • @jaimev321
    @jaimev321 ปีที่แล้ว

    Thanks

  • @kader8815
    @kader8815 9 หลายเดือนก่อน

    can i use dfir-iris without docker ??

  • @S0GE_KING
    @S0GE_KING 10 หลายเดือนก่อน

    How much memory do I need to allocate on the server for it??

  • @mkhalileng
    @mkhalileng ปีที่แล้ว

    thank you for your effort.
    Could you make video for latest version 2.3 ?
    😅

    • @erosonthekitchen
      @erosonthekitchen ปีที่แล้ว +1

      Did you manage to install version 2.3? It doesn't work for me, it won't start on port 443, it keeps telling me that the website is sleeping.

  • @JorgeAntonioArca
    @JorgeAntonioArca 2 ปีที่แล้ว

    Hola, de donde sacan los eventos?

  • @ak414414
    @ak414414 2 ปีที่แล้ว

    Can ElastAlert send alert to DFIR-IRIS ?

  • @mmahrusqusaeri1326
    @mmahrusqusaeri1326 2 ปีที่แล้ว

    cool, i will try this

  • @lyledocherty4356
    @lyledocherty4356 ปีที่แล้ว

    Hi There,
    Wondering if anyone would be able to assist me with something, I have had some struggled with DFIR IRIS and getting it up and running but I have now managed to get it working, however when I try to find the admin password to sign into the portal it states:
    WARNING :: post_init :: create_safe_admin :: >>> Administrator already exists
    Wondering if anyone else had come across this and what they did to fix it, I can't seem to see a log of the admin password anywhere, I have checked the docker logs and still don't appear to see it it just states Administrator already exists, any help is much appreciated.

  • @EminKmmm
    @EminKmmm 2 ปีที่แล้ว

    awesome

  • @aramisdelacruz8879
    @aramisdelacruz8879 8 หลายเดือนก่อน

    Hello, has anyone here been able to generate automatic alerts once they match with MISP or some other threat intelligence tool, using graylog for log management?

    • @Muhammad-re4wk
      @Muhammad-re4wk 3 หลายเดือนก่อน

      Yes we have done this where I work

  • @cod_010
    @cod_010 2 ปีที่แล้ว

    How did you get the Virus total API Key?

    • @ithiou92
      @ithiou92 2 ปีที่แล้ว

      On virus total plateform after creating an account you can request the API key

    • @DeadlyDragon_
      @DeadlyDragon_ ปีที่แล้ว

      Something to note ifor others who may see this there is a rather small API limit for virustotal.