IR / DFIR Lab Preset
The IR/DFIR Lab preset deploys a forensics-focused stack: Velociraptor for endpoint collection, TheHive for case management, DFIR-IRIS for evidence tracking, and OpenCTI for threat intelligence context.
This preset is optimized for incident response training and active investigations. Deploy time is 10–14 minutes. Cost: approximately $0.80–$1.20/hour.
Included tools
Velociraptor
Forensics
Live endpoint artifact collection and fleet hunting
TheHive
Case Mgmt
Incident case creation, task tracking, and team coordination
DFIR-IRIS
IR
Evidence management, IOC tracking, and investigation timeline
OpenCTI
CTI
Threat intelligence — enrich IOCs with actor and campaign context