Ingest OCSF alerts, enrich with plugins, and perform case investigations. Built for analysts.
Get Started on GitHubExtend Console-IR with a growing ecosystem of enrichments and connectors.

IP geolocation enrichment for context on alerts.

Domain registration and ownership lookups.

AI-powered summarization and case assistance.

Threat intel aggregation and lookups.

Integration with MISP for indicators and events.

Graph-based threat intelligence platform connector.
Get the free community edition from GitHub and start investigating faster.
View on GitHubYes — on‑prem and air‑gapped deployments supported.
Local SQLite with full-text search; optional centralized storage for enterprise.
yes you can bring your licence/api key
custom plugins via streams.