Welcome, Analyst
DFIR Lab is an independent research platform for digital forensics, incident response, and threat intelligence — built by practitioners, for practitioners. Here's what you'll find.
Security Research & Threat Intelligence
In-depth analysis of threats, hands-on lab testing, detection engineering, and security tooling — by a practitioner, for practitioners.
Subscribe to receive curated threat intelligence briefings — CVEs, malware trends, and MITRE ATT&CK insights delivered straight to your inbox.
Build a Splunk custom search command that enriches IOCs via DFIR Platform API. Includes Python code, commands.conf configuration, packaging as a Splunk app, and example SPL queries.
Integrate DFIR Platform's IOC enrichment API with Wazuh for real-time alert enrichment. Includes integratord configuration, active response scripts, and example alert workflows for SOC teams.
Integrate DFIR Platform's multi-source IOC enrichment API with TheHive as a Cortex analyzer. Python code examples, architecture walkthrough, and step-by-step setup for SOC teams.
Free tier · No credit card required