Skip to main content

Yeti

Open-source threat intelligence and forensics platform for storage, correlation, and export of IOCs, TTPs, and DFIR artifacts.

Technical Architecture & Overview

Yeti is an open-source threat intelligence and forensics platform that stores, correlates, and exports indicators of compromise, TTPs, and DFIR artifacts. It bridges cyber threat intelligence and DFIR workflows through a web interface, REST API, and enrichment pipeline.

Targeted Technical Use Cases

Centralizing technical threat intelligence and DFIR artifacts for investigations and IOC enrichment.

Evaluation & Trade-offs

Core Strengths

  • +Combines CTI and DFIR artifact management in a single platform.
  • +Supports YARA, Sigma, DFIQ, and bulk observable searches.
  • +Provides an API and pluggable feeds for automation and integration.

Trade-Offs & Limitations

  • -Requires dedicated infrastructure and maintenance for production deployments.
  • -Smaller community than MISP, with fewer ready-made feed integrations.

Defensive Security Application

Enriching incident investigations, tracking adversary TTPs, and exporting IOCs to SIEM and detection tools.

Frequently Asked Questions

What is Yeti?

Yeti is an open-source threat intelligence and forensics platform that stores, correlates, and exports indicators of compromise, TTPs, and DFIR artifacts. It bridges cyber threat intelligence and DFIR workflows through a web interface, REST API, and enrichment pipeline.

What is Yeti used for?

Centralizing technical threat intelligence and DFIR artifacts for investigations and IOC enrichment.

What are the strengths of Yeti?
  • +Combines CTI and DFIR artifact management in a single platform.
  • +Supports YARA, Sigma, DFIQ, and bulk observable searches.
  • +Provides an API and pluggable feeds for automation and integration.
What are the limitations of Yeti?
  • +Requires dedicated infrastructure and maintenance for production deployments.
  • +Smaller community than MISP, with fewer ready-made feed integrations.
How is Yeti used defensively?

Enriching incident investigations, tracking adversary TTPs, and exporting IOCs to SIEM and detection tools.