Ingest OCSF alerts, enrich with powerful plugins, and perform comprehensive case investigations. Built by analysts, for analysts who demand speed and precision.
Watch how Console-IR streamlines incident response workflows with keyboard-first efficiency.
Extend Console-IR with a growing ecosystem of enrichments and connectors. Build your perfect investigation workflow.
IP geolocation enrichment for context on alerts.
Domain registration and ownership lookups.
AI-powered summarization and case assistance.
Threat intel aggregation and lookups.
Integration with MISP for indicators and events.
Graph-based threat intelligence platform connector.
Enterprise-grade incident response capabilities designed for modern security teams.
Get Console-IR for free from GitHub and start investigating faster today.
View on GitHubYes — on-prem and air-gapped deployments are fully supported. Console-IR is designed to work in environments with strict security requirements, including completely isolated networks.
Local SQLite with full-text search capabilities for fast queries. For enterprise deployments, optional centralized storage solutions are available to support multi-user collaboration.
Yes, you can bring your own license/API key. Console-IR supports pluggable LLM integrations, allowing you to use your preferred AI provider or run models locally.
Custom plugins via streams architecture. Build your own integrations or use community plugins for GeoIP, Whois, MISP, OpenCTI, IntelOwl, and more.
Console-IR is open source and community-driven. For enterprise support, training, and custom development, reach out through our GitHub repository.