Yeti is a forensics intelligence platform that bridges CTI and DFIR by enabling bulk threat observable searches and threat-focused investigations.
Your Everyday Threat Intelligence
Yeti is designed for CTI analysts and DFIR teams to efficiently search, correlate, and analyze threat intelligence and forensic artifacts. It helps answer questions like where an artifact has been seen before and provides a backend for DFIR queries, making it ideal for incident response and threat hunting workflows.
Yeti is primarily a backend platform with a web API and web interface; users should refer to the official documentation for detailed setup and integration instructions. It is best used in environments where CTI and DFIR workflows intersect, and users should consider integrating it with existing SIEM and incident management tools.