Yeti
Open-source threat intelligence and forensics platform for storage, correlation, and export of IOCs, TTPs, and DFIR artifacts.
Technical Architecture & Overview
Yeti is an open-source threat intelligence and forensics platform that stores, correlates, and exports indicators of compromise, TTPs, and DFIR artifacts. It bridges cyber threat intelligence and DFIR workflows through a web interface, REST API, and enrichment pipeline.
Targeted Technical Use Cases
Centralizing technical threat intelligence and DFIR artifacts for investigations and IOC enrichment.
Evaluation & Trade-offs
Core Strengths
- +Combines CTI and DFIR artifact management in a single platform.
- +Supports YARA, Sigma, DFIQ, and bulk observable searches.
- +Provides an API and pluggable feeds for automation and integration.
Trade-Offs & Limitations
- -Requires dedicated infrastructure and maintenance for production deployments.
- -Smaller community than MISP, with fewer ready-made feed integrations.
Defensive Security Application
Enriching incident investigations, tracking adversary TTPs, and exporting IOCs to SIEM and detection tools.
Frequently Asked Questions
What is Yeti?→
Yeti is an open-source threat intelligence and forensics platform that stores, correlates, and exports indicators of compromise, TTPs, and DFIR artifacts. It bridges cyber threat intelligence and DFIR workflows through a web interface, REST API, and enrichment pipeline.
What is Yeti used for?→
Centralizing technical threat intelligence and DFIR artifacts for investigations and IOC enrichment.
What are the strengths of Yeti?→
- +Combines CTI and DFIR artifact management in a single platform.
- +Supports YARA, Sigma, DFIQ, and bulk observable searches.
- +Provides an API and pluggable feeds for automation and integration.
What are the limitations of Yeti?→
- +Requires dedicated infrastructure and maintenance for production deployments.
- +Smaller community than MISP, with fewer ready-made feed integrations.
How is Yeti used defensively?→
Enriching incident investigations, tracking adversary TTPs, and exporting IOCs to SIEM and detection tools.